Session Fixation in GitHub repository filegator/filegator prior to 7.8.0.
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
Link | Tags |
---|---|
https://huntr.dev/bounties/881f8f36-d5c8-470d-8261-f109e6d5db4b | exploit third party advisory patch |
https://github.com/filegator/filegator/commit/fcd3995f64f5dfc6a4c2c059cc22a2fef1e81225 | third party advisory patch |