CyberRota Analysis
AI-GeneratedThe s-pms SPMS-Server application contains a hardcoded default access token secret in its core configuration file, which remains unchanged in production environments. This vulnerability allows remote, unauthenticated attackers to forge valid administrative session tokens, enabling them to bypass authentication and gain full unauthorized access to protected backend APIs. Organizations using this application should prioritize remediation to prevent potential exploitation and unauthorized access to sensitive data.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
An issue was discovered in s-pms SPMS-Server through v1.0. The application contains a hardcoded default access token secret within its core configuration file, which is not overridden or removed in the production environment profile. A remote, unauthenticated attacker can locally forge valid administrative session tokens to completely bypass the authentication mechanism gaining full unauthorized access to protected backend APIs.