Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w6pf-cx8p-259q

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

Invision Power Services (IPS) Community Suite before 4.1.9 makes session hijack easier by relying on the PHP uniqid function without the more_entropy flag. Attackers can guess an Invision Power Board session cookie if they can predict the exact time of cookie generation.

Invision Power Services (IPS) Community Suite before 4.1.9 makes session hijack easier by relying on the PHP uniqid function without the more_entropy flag. Attackers can guess an Invision Power Board session cookie if they can predict the exact time of cookie generation.

EPSS

Процентиль: 53%
0.00305
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-331

Связанные уязвимости

CVSS3: 5.9
nvd
почти 9 лет назад

Invision Power Services (IPS) Community Suite before 4.1.9 makes session hijack easier by relying on the PHP uniqid function without the more_entropy flag. Attackers can guess an Invision Power Board session cookie if they can predict the exact time of cookie generation.

EPSS

Процентиль: 53%
0.00305
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-331