VYPR
Medium severity6.5NVD Advisory· Published Sep 9, 2019· Updated Jun 17, 2026

CVE-2019-16133

CVE-2019-16133

Description

An issue was discovered in eteams OA v4.0.34. Because the session is not strictly checked, the account names and passwords of all employees in the company can be obtained by an ordinary account. Specifically, the attacker sends a jsessionid value for URIs under app/profile/summary/.

Affected products

3

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.