The MobileUI (aka RT-Extension-MobileUI) extension before 1.04 in Request Tracker (RT) 4.0.0 before 4.0.13, when using the file-based session store (Apache::Session::File) and certain authentication extensions, allows remote attackers to reuse unauthorized sessions and obtain user preferences and caches via unspecified vectors.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.osvdb.org/94280 | vdb entry |
http://lists.bestpractical.com/pipermail/rt-announce/2013-June/000230.html | patch mailing list |
http://secunia.com/advisories/53799 | third party advisory |