Описание
A low privileged remote attacker can hijack an active administrative session without needing to know the administrator password by extracting live plaintext session identifiers for authenticated users from downloadable error log archives.
EPSS
Процентиль: 34%
0.004
Низкий
8.8 High
CVSS3
Дефекты
CWE-532
Связанные уязвимости
CVSS3: 8.8
github
около 1 месяца назад
A low privileged remote attacker can hijack an active administrative session without needing to know the administrator password by extracting live plaintext session identifiers for authenticated users from downloadable error log archives.
EPSS
Процентиль: 34%
0.004
Низкий
8.8 High
CVSS3
Дефекты
CWE-532