Medium severity6.5NVD Advisory· Published Mar 30, 2022· Updated Jun 17, 2026
CVE-2021-45900
CVE-2021-45900
Description
Vivoh Webinar Manager before 3.6.3.0 has improper API authentication. When a user logs in to the administration configuration web portlet, a VIVOH_AUTH cookie is assigned so that they can be uniquely identified. Certain APIs can be successfully executed without proper authentication. This can let an attacker impersonate as victim and make state changing requests on their behalf.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:vivoh:webinar_manager:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:vivoh:webinar_manager:*:*:*:*:*:*:*:*range: <3.6.3.0
- (no CPE)range: <3.6.3.0
- Vivoh/Webinar Managerdescription
Patches
Vulnerability mechanics
References
2- vivoh.com/blog/finra-remediation/nvdExploitVendor Advisory
- vivoh.com/wp-content/uploads/2021/11/Vivoh-Webinar-Manager-for-Zoom-Installation-and-Administration-Guide.pdfnvdBroken Link
News mentions
0No linked articles in our index yet.