CVE-2021-42338 is a critical authentication bypass vulnerability affecting 4MOSAn GCB Doctor's login page, stemming from improper cookie validation. This allows unauthenticated remote attackers to inject code into cookies, bypass authentication, and achieve arbitrary file upload and execution, leading to system manipulation or service interruption. With a CVSS score of 9.8 (Critical), the attack is network-based, low complexity, and requires no user interaction, resulting in high impacts to confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the high FAUCET Risk Score indicates significant potential danger.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 20210708CPE matchmatch criteria | cpe:2.3:a:4mosan:gcb_doctor:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.