VYPR
Medium severity6.5NVD Advisory· Published Mar 30, 2022· Updated Jun 17, 2026

CVE-2021-45900

CVE-2021-45900

Description

Vivoh Webinar Manager before 3.6.3.0 has improper API authentication. When a user logs in to the administration configuration web portlet, a VIVOH_AUTH cookie is assigned so that they can be uniquely identified. Certain APIs can be successfully executed without proper authentication. This can let an attacker impersonate as victim and make state changing requests on their behalf.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:vivoh:webinar_manager:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:vivoh:webinar_manager:*:*:*:*:*:*:*:*range: <3.6.3.0
    • (no CPE)range: <3.6.3.0
  • Vivoh/Webinar Managerdescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.