CVE-2025-27223 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints such as /trufusionPortal/getProjectList.…
High CVSS: 7.5

CVE-2025-27223

TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints such as /trufusionPortal/getProjectList. However, the application uses a static key to create the encrypted cookie, ultimately allowing anyone to forge cookies and gain access to sensitive internal information.
Vendor
Rocketsoftware
Product
Trufusion Enterprise
CWE
CWE-1004
Yayın Tarihi
2025-10-27 17:15:37
Güncelleme
2025-10-31 20:35:08
Source Identifier
cve@mitre.org
KEV Date Added
-

Kategoriler

Referanslar