Описание
Creativeitem Academy LMS up to and including 5.13 does not regenerate session IDs upon successful authentication, enabling session fixation attacks where attackers can hijack user sessions by predetermining session identifiers.
Ссылки
- ExploitMitigationThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 5.13 (включая)
cpe:2.3:a:creativeitem:academy_lms:*:*:*:*:*:*:*:*
EPSS
Процентиль: 5%
0.0002
Низкий
2.2 Low
CVSS3
Дефекты
CWE-384
Связанные уязвимости
CVSS3: 2.2
github
4 месяца назад
Creativeitem Academy LMS up to and including 5.13 does not regenerate session IDs upon successful authentication, enabling session fixation attacks where attackers can hijack user sessions by predetermining session identifiers.
EPSS
Процентиль: 5%
0.0002
Низкий
2.2 Low
CVSS3
Дефекты
CWE-384