Логотип exploitDog
bind:CVE-2025-53021
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-53021

Количество 4

Количество 4

ubuntu логотип

CVE-2025-53021

около 1 месяца назад

A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being linked to the attacker's. Successful exploitation results in full account takeover. According to the Moodle Releases page, "Bug fixes for security issues in 3.11.x ended 11 December 2023." NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 4.2
EPSS: Низкий
nvd логотип

CVE-2025-53021

около 1 месяца назад

A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being linked to the attacker's. Successful exploitation results in full account takeover. According to the Moodle Releases page, "Bug fixes for security issues in 3.11.x ended 11 December 2023." NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 4.2
EPSS: Низкий
debian логотип

CVE-2025-53021

около 1 месяца назад

A session fixation vulnerability in Moodle 3.x through 3.11.18 allows ...

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-cgvv-3455-824j

около 1 месяца назад

Moodle Session Fixation allows unauthenticated users to hijack sessions via sesskey parameter

CVSS3: 4.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-53021

A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being linked to the attacker's. Successful exploitation results in full account takeover. According to the Moodle Releases page, "Bug fixes for security issues in 3.11.x ended 11 December 2023." NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 4.2
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2025-53021

A session fixation vulnerability in Moodle 3.x through 3.11.18 allows unauthenticated attackers to hijack user sessions via the sesskey parameter. The sesskey can be obtained without authentication and reused within the OAuth2 login flow, resulting in the victim's session being linked to the attacker's. Successful exploitation results in full account takeover. According to the Moodle Releases page, "Bug fixes for security issues in 3.11.x ended 11 December 2023." NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

CVSS3: 4.2
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2025-53021

A session fixation vulnerability in Moodle 3.x through 3.11.18 allows ...

CVSS3: 4.2
0%
Низкий
около 1 месяца назад
github логотип
GHSA-cgvv-3455-824j

Moodle Session Fixation allows unauthenticated users to hijack sessions via sesskey parameter

CVSS3: 4.2
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу