CVE-2023-6451: Alayacare Procura
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
Publicly known cryptographic machine key in AlayaCare's Procura Portal before 9.0.1.2 allows attackers to forge their own authentication cookies and bypass the application's authentication mechanisms.
Affected products
- Alayacare Procura: before 9.0.1.2 (fixed in 9.0.1.2)
Published 2024-02-16. Last modified 2026-06-17.