Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jh98-qr76-24j7

Опубликовано: 25 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 5.5

Описание

An Incorrect Implementation of Authentication Algorithm and Exposure of Data Element to Wrong Ses-sion vulnerability in the session handling used in B&R APROL <4.4-00P5 may allow an authenticated network attacker to take over a currently active user session without login credentials.

An Incorrect Implementation of Authentication Algorithm and Exposure of Data Element to Wrong Ses-sion vulnerability in the session handling used in B&R APROL <4.4-00P5 may allow an authenticated network attacker to take over a currently active user session without login credentials.

EPSS

Процентиль: 22%
0.0007
Низкий

5.5 Medium

CVSS4

Дефекты

CWE-303

Связанные уязвимости

nvd
11 месяцев назад

An Incorrect Implementation of Authentication Algorithm and Exposure of Data Element to Wrong Ses-sion vulnerability in the session handling used in B&R APROL <4.4-00P5 may allow an authenticated network attacker to take over a currently active user session without login credentials.

EPSS

Процентиль: 22%
0.0007
Низкий

5.5 Medium

CVSS4

Дефекты

CWE-303