The server checks the user's cookie in a non-standard way, and a value is entered in the cookie value name of the status and its value is set to true to bypass the identification with the system using a username and password.
References
Link | Resource |
---|---|
https://www.gov.il/en/Departments/faq/cve_advisories | Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2022-07-18 06:15
Updated : 2022-07-22 19:08
NVD link : CVE-2022-30623
Mitre link : CVE-2022-30623
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
chcnav
- p5e_gnss
- p5e_gnss_firmware