CVE-2025-27223 Details
Description
TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints such as /trufusionPortal/getProjectList. However, the application uses a static key to create the encrypted cookie, ultimately allowing anyone to forge cookies and gain access to sensitive internal information.
A vulnerability in TRUfusion Enterprise versions through 7.10.4.0 allows for session cookie forgery due to the use of a hard-coded cryptographic key. The application encrypts authentication cookies with a static key, enabling unauthorized access to sensitive internal information by bypassing authentication. Exploitation of this vulnerability can be done by manipulating the 'COOKIEID' or 'ADMINCOOKIEID' cookies, which are used to authenticate users on certain endpoints, such as '/trufusionPortal/getProjectList'.
Users are advised to update to TRUfusion Enterprise versions 7.10.3.1, 7.10.1.1, 7.10.1.0, 7.10.3.0, 7.9.4.0, 7.9.6.1, 7.9.6.0, 7.9.3.0, 7.9.3.1, 7.9.2.1, 7.10.0.1, 7.9.5.0 or 7.10.2.0.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 28, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1004 | Sensitive Cookie Without 'HttpOnly' Flag | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| rocketsoftware trufusion enterprise | <= 7.10.4.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 31, 2025 | Initial Analysis | [email protected] |
| Oct 28, 2025 | CVE Modified | CISA-ADP |
| Oct 27, 2025 | New CVE Received | [email protected] |