
CVE-2020-8434
https://notcve.org/view.php?id=CVE-2020-8434
19 May 2020 — Jenzabar JICS (aka Internet Campus Solution) before 9.0.1 Patch 3, 9.1 before 9.1.2 Patch 2, and 9.2 before 9.2.2 Patch 8 has session cookies that are a deterministic function of the username. There is a hard-coded password to supply a PBKDF feeding into AES to encrypt a username and base64 encode it to a client-side cookie for persistent session authentication. By knowing the key and algorithm, an attacker can select any username, encrypt it, base64 encode it, and save it in their browser with the correct ... • https://medium.com/%40mdavis332/higher-ed-erp-portal-vulnerability-auth-bypass-to-login-any-account-f1aeef438f80 • CWE-384: Session Fixation •

CVE-2019-10011
https://notcve.org/view.php?id=CVE-2019-10011
25 Mar 2019 — ICS/StaticPages/AddTestUsers.aspx in Jenzabar JICS (aka Internet Campus Solution) before 2019-02-06 allows remote attackers to create an arbitrary number of accounts with a password of 1234. ICS/StaticPages/AddTestUsers.aspx en Jenzabar JICS (también conocida como Internet Campus Solution) anterior a 2019-02-06 permite a los atacantes remotos crear un número arbitrario de cuentas con una contraseña de 1234. • https://medium.com/%40mdavis332/higher-ed-erp-portal-vulnerability-create-your-own-accounts-d865bd22cdd8 • CWE-798: Use of Hard-coded Credentials •