CVE-2025-27223

TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints such as /trufusionPortal/getProjectList. However, the application uses a static key to create the encrypted cookie, ultimately allowing anyone to forge cookies and gain access to sensitive internal information.
Configurations

Configuration 1 (hide)

cpe:2.3:a:rocketsoftware:trufusion_enterprise:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-10-27 17:15

Updated : 2025-10-31 20:35


NVD link : CVE-2025-27223

Mitre link : CVE-2025-27223

CVE.ORG link : CVE-2025-27223


JSON object : View

Products Affected

rocketsoftware

  • trufusion_enterprise
CWE
CWE-1004

Sensitive Cookie Without 'HttpOnly' Flag