CVE-2025-27223 Scanner
CVE-2025-27223 Scanner - Authentication Bypass vulnerability in TRUfusion Enterprise
Used 3k times · 3.3k assets checked · domain, subdomain, ipv4
TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints such as /trufusionPortal/getProjectList. However, the application uses a static key to create the encrypted cookie, ultimately allowing anyone to forge cookies and gain access to sensitive internal information.
CVE-2025-27223 Scanner - Authentication Bypass vulnerability in TRUfusion Enterprise
Used 3k times · 3.3k assets checked · domain, subdomain, ipv4
S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.
Create a free account →