Логотип exploitDog
bind:CVE-2018-16495
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-16495

Количество 2

Количество 2

nvd логотип

CVE-2018-16495

больше 4 лет назад

In VOS user session identifier (authentication token) is issued to the browser prior to authentication but is not changed after the user successfully logs into the application. Failing to issue a new session ID following a successful login introduces the possibility for an attacker to set up a trap session on the device the victim is likely to login with.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-gvq8-8f97-wwvq

больше 3 лет назад

In VOS user session identifier (authentication token) is issued to the browser prior to authentication but is not changed after the user successfully logs into the application. Failing to issue a new session ID following a successful login introduces the possibility for an attacker to set up a trap session on the device the victim is likely to login with.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2018-16495

In VOS user session identifier (authentication token) is issued to the browser prior to authentication but is not changed after the user successfully logs into the application. Failing to issue a new session ID following a successful login introduces the possibility for an attacker to set up a trap session on the device the victim is likely to login with.

CVSS3: 8.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-gvq8-8f97-wwvq

In VOS user session identifier (authentication token) is issued to the browser prior to authentication but is not changed after the user successfully logs into the application. Failing to issue a new session ID following a successful login introduces the possibility for an attacker to set up a trap session on the device the victim is likely to login with.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу