givanz Vvveb session fixiation
13Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 5.3epss 0.7%
probabilidade de exploração
0.7%top 52% das CVEs
exploração observada
nãonenhuma fonte reporta
A vulnerability was detected in givanz Vvveb 1.0.6.1. Impacted is an unknown function. The manipulation results in session fixiation. The attack can be launched remotely. The exploit is now public and may be used. Upgrading to version 1.0.7 is recommended to address this issue. The patch is identified as d4b1e030066417b77d15b4ac505eed5ae7bf2c5e. You should upgrade the affected component.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Produtos afetados
givanz · VvvebReferências
https://github.com/givanz/Vvveb/commit/d4b1e030066417b77d15b4ac505eed5ae7bf2c5ehttps://github.com/givanz/Vvveb/issues/312https://github.com/givanz/Vvveb/issues/312#issuecomment-2977995664https://github.com/givanz/Vvveb/releases/tag/1.0.7https://github.com/helloandrewpaul/Session-Fixation-in-Vvveb-CMS-v1.0.6.1https://github.com/kwerty138/Session-Fixation-in-Vvveb-CMS-v1.0.6.1https://vuldb.com/?ctiid.318643https://vuldb.com/?id.318643https://vuldb.com/?submit.623135