KTM System e-BOK是KTM System公司的一款电子出纳管理软件。 KTM System e-BOK 06.2026之前版本存在会话机制问题漏洞,该漏洞源于会话标识符在身份验证前可被客户端设置,若设置有效名称的Cookie,其值在成功登录后保持不变,使攻击者可固定受害者的会话ID,随后劫持已认证的会话。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| KTM System | e-BOK | < 06.2026 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| KTM System | e-BOK | 0 ~ 06.2026 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-35098 | Improper Restriction of Excessive Authentication Attempts in KTM System e-BOK | |
| CVE-2026-35096 | Cross-Site Request Forgery (CSRF) in KTM System e-BOK | |
| CVE-2026-35097 | Weak Password Requirements in KTM System e-BOK |
No comments yet