Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-12115 | Due to improper JSON Web Tokens implementation an unauthenticated remote attacker can guess a valid session ID and therefore impersonate a user to gain full access. |
Thu, 24 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 24 Apr 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Due to improper JSON Web Tokens implementation an unauthenticated remote attacker can guess a valid session ID and therefore impersonate a user to gain full access. | |
| Title | Improper session handling | |
| Weaknesses | CWE-613 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2025-04-24T15:22:23.071Z
Reserved: 2025-03-17T08:25:16.736Z
Link: CVE-2021-47663
Updated: 2025-04-24T13:48:10.195Z
Status : Deferred
Published: 2025-04-24T10:15:16.703
Modified: 2026-04-15T00:35:42.020
Link: CVE-2021-47663
No data.
OpenCVE Enrichment
No data.
EUVD