Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v76g-p5xj-4qm7

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

SQL-Ledger 2.4.4 through 2.6.17 authenticates users by verifying that the value of the sql-ledger-[username] cookie matches the value of the sessionid parameter, which allows remote attackers to gain access as any logged-in user by setting the cookie and the parameter to the same value.

SQL-Ledger 2.4.4 through 2.6.17 authenticates users by verifying that the value of the sql-ledger-[username] cookie matches the value of the sessionid parameter, which allows remote attackers to gain access as any logged-in user by setting the cookie and the parameter to the same value.

EPSS

Процентиль: 79%
0.01337
Низкий

Дефекты

CWE-287

Связанные уязвимости

ubuntu
около 19 лет назад

SQL-Ledger 2.4.4 through 2.6.17 authenticates users by verifying that the value of the sql-ledger-[username] cookie matches the value of the sessionid parameter, which allows remote attackers to gain access as any logged-in user by setting the cookie and the parameter to the same value.

nvd
около 19 лет назад

SQL-Ledger 2.4.4 through 2.6.17 authenticates users by verifying that the value of the sql-ledger-[username] cookie matches the value of the sessionid parameter, which allows remote attackers to gain access as any logged-in user by setting the cookie and the parameter to the same value.

debian
около 19 лет назад

SQL-Ledger 2.4.4 through 2.6.17 authenticates users by verifying that ...

EPSS

Процентиль: 79%
0.01337
Низкий

Дефекты

CWE-287