Описание
Invision Power Services (IPS) Community Suite before 4.1.9 makes session hijack easier by relying on the PHP uniqid function without the more_entropy flag. Attackers can guess an Invision Power Board session cookie if they can predict the exact time of cookie generation.
Ссылки
- Release NotesVendor Advisory
- Release NotesVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.1.8.1 (включая)
cpe:2.3:a:invisioncommunity:invision_power_board:*:*:*:*:*:*:*:*
EPSS
Процентиль: 53%
0.00305
Низкий
5.9 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-331
Связанные уязвимости
CVSS3: 5.9
github
больше 3 лет назад
Invision Power Services (IPS) Community Suite before 4.1.9 makes session hijack easier by relying on the PHP uniqid function without the more_entropy flag. Attackers can guess an Invision Power Board session cookie if they can predict the exact time of cookie generation.
EPSS
Процентиль: 53%
0.00305
Низкий
5.9 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-331