Session Fixation in GitHub repository snipe/snipe-it prior to 6.0.10.
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
Link | Tags |
---|---|
https://huntr.dev/bounties/c09bf21b-50d2-49f0-8c92-49f6b3c358d8 | exploit third party advisory patch |
https://github.com/snipe/snipe-it/commit/6fde72a69335c80079363b7d26aa94e7f67400e1 | third party advisory patch |