← Back to browse · API

CVE-2021-22860

Severity
CRITICAL
CVSS
9.8
EPSS
0.02558
Risk score
40.1
CISA KEV
No
PoC
No
Published
2021-03-17
Modified
2024-09-16
First seen
2026-08-07
Aliases
EUVD-2021-9995, GHSA-WHG3-7342-P9MG
Products
Excellent Infotek Corporation:e-document system 0 2.9, Excellent Infotek Corporation:e-document system 0 3.0.2
Sources
euvd EUVD-2021-9995

Description

EIC e-document system does not perform completed identity verification for sorting and filtering personnel data. The vulnerability allows remote attacker to obtain users’ credential information without logging in the system, and further acquire the privileged permissions and execute arbitrary commends.

References