CVE-2025-2395
The U-Office Force from e-Excellence has an Improper Authentication vulnerability, allowing unauthenticated remote attackers to use a particular API and alter cookies to log in as an administrator.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.57%
- CWE
- CWE-565
- Published
- 2025-03-17
- Last modified
- 2026-03-12
Affected products
- e-Excellence U-Office Force
Weakness type
Related vulnerabilities
- CVE-2026-85181 — CAT through 3.1.0 Session Cookie Forgery via Unkeyed hashCode Checksum
- CVE-2026-75757 — AshAdmin cookie reader matches names by substring, enabling actor/session shadowing from a sibling subdomain
- CVE-2026-53871 — Hermes WebUI < 0.51.368 - Profile-Scoped Authorization Bypass via Forged hermes_profile Cookie
- CVE-2026-8337 — Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys when sites are running concurrent public surveys and private surveys
- CVE-2026-0257 — PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
- CVE-2026-39963 — Serendipity: Host Header Injection enables authentication cookie scoping to an attacker-controlled domain
- CVE-2026-39324 — Rack::Session::Cookie secrets: decrypt failure fallback enables secretless session forgery and Marshal deserialization
- CVE-2026-5130 — Debugger & Troubleshooter <= 1.3.2 - Unauthenticated Privilege Escalation to Administrator via Cookie Manipulation