CVE-2025-2395

The U-Office Force from e-Excellence has an Improper Authentication vulnerability, allowing unauthenticated remote attackers to use a particular API and alter cookies to log in as an administrator.
Configurations

Configuration 1 (hide)

cpe:2.3:a:edetw:u-office_force:*:*:*:*:*:*:*:*

History

18 Nov 2025, 17:46

Type Values Removed Values Added
CPE cpe:2.3:a:edetw:u-office_force:*:*:*:*:*:*:*:*
First Time Edetw
Edetw u-office Force
Summary
  • (es) U-Office Force de e-Excellence tiene una vulnerabilidad de autenticación incorrecta, que permite a atacantes remotos no autenticados utilizar una API particular y alterar las cookies para iniciar sesión como administrador.
References () https://www.twcert.org.tw/en/cp-139-10012-d5bbc-2.html - () https://www.twcert.org.tw/en/cp-139-10012-d5bbc-2.html - Third Party Advisory
References () https://www.twcert.org.tw/tw/cp-132-10011-3de72-1.html - () https://www.twcert.org.tw/tw/cp-132-10011-3de72-1.html - Third Party Advisory

17 Mar 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-17 06:15

Updated : 2025-11-18 17:46


NVD link : CVE-2025-2395

Mitre link : CVE-2025-2395

CVE.ORG link : CVE-2025-2395


JSON object : View

Products Affected

edetw

  • u-office_force
CWE
CWE-565

Reliance on Cookies without Validation and Integrity Checking