Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cqx4-jqpq-wx8p

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

rConfig 3.9.4 is vulnerable to session fixation because session expiry and randomization are mishandled. The application can reuse a session via PHPSESSID. Also, an attacker can exploit this vulnerability in conjunction with CVE-2020-12256 or CVE-2020-12259.

rConfig 3.9.4 is vulnerable to session fixation because session expiry and randomization are mishandled. The application can reuse a session via PHPSESSID. Also, an attacker can exploit this vulnerability in conjunction with CVE-2020-12256 or CVE-2020-12259.

EPSS

Процентиль: 77%
0.01064
Низкий

Связанные уязвимости

CVSS3: 9.1
nvd
больше 5 лет назад

rConfig 3.9.4 is vulnerable to session fixation because session expiry and randomization are mishandled. The application can reuse a session via PHPSESSID. Also, an attacker can exploit this vulnerability in conjunction with CVE-2020-12256 or CVE-2020-12259.

EPSS

Процентиль: 77%
0.01064
Низкий