CVE-2020-23178 - CERT CVE
ID CVE-2020-23178
Sažetak An issue exists in PHP-Fusion 9.03.50 where session cookies are not deleted once a user logs out, allowing for an attacker to perform a session replay attack and impersonate the victim user.
Reference
CVSS
Base: 5.5
Impact: 4.9
Exploitability:8.0
Pristup
VektorSloženostAutentikacija
NETWORK LOW SINGLE
Impact
PovjerljivostCjelovitostDostupnost
PARTIAL PARTIAL NONE
CVSS vektor AV:N/AC:L/Au:S/C:P/I:P/A:N
Zadnje važnije ažuriranje 06-07-2021 - 14:10
Objavljeno 02-07-2021 - 18:15