Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hg4g-pqvm-c557

Опубликовано: 27 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

HTTP::Session2 versions through 1.09 for Perl does not validate the format of user provided session ids, enabling code injection or other impact depending on session backend.

For example, if an application uses memcached for session storage, then it may be possible for a remote attacker to inject memcached commands in the session id value.

HTTP::Session2 versions through 1.09 for Perl does not validate the format of user provided session ids, enabling code injection or other impact depending on session backend.

For example, if an application uses memcached for session storage, then it may be possible for a remote attacker to inject memcached commands in the session id value.

EPSS

Процентиль: 32%
0.00404
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 6.5
nvd
4 месяца назад

HTTP::Session2 versions through 1.09 for Perl does not validate the format of user provided session ids, enabling code injection or other impact depending on session backend. For example, if an application uses memcached for session storage, then it may be possible for a remote attacker to inject memcached commands in the session id value.

EPSS

Процентиль: 32%
0.00404
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-20