9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
Official Document Management System developed by 2100 Technology has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to obtain any user's connection token and use it to log into the system as that user.
Basic Information
ID
CVE-2025-8853
Source
twcert
Published
Aug 11, 2025 at 09:04
Affected Product
Vendor
2100 Technology
Product
Official Document Management System
Version
5.0.89.0
Affected Versions
2100 Technology Official Document Management System 5.0.89.0
2100 Technology Official Document Management System 5.0.89.1
2100 Technology Official Document Management System 5.0.89.2
2100 Technology Official Document Management System 5.0.89.1
2100 Technology Official Document Management System 5.0.89.2