Session disclosure inside the log files
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 4.7epss 0.3%
exploitation probability
0.3%top 83% of all CVEs
observed exploitation
nono source reports it
In short
Admin login cookies are saved in plain text in log files, allowing attackers to steal them and gain unauthorized access to administrator accounts.
Technical detail
CWE-1295 involves storing sensitive authentication tokens in plaintext logs accessible to threat actors. An attacker with log file access can extract admin session cookies and use them to bypass authentication controls. This requires local or remote log access but enables complete account takeover of administrative accounts.
Summary generated and translated by AI from the official description.
Admin cookies are written in clear-text in logs. An attacker can retrieve them and bypass the authentication mechanism. As for the affected products/models/versions, see the reference URL.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N