Session Fixation in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
Link | Tags |
---|---|
https://huntr.dev/bounties/de213e0b-a227-4fc3-bbe7-0b33fbf308e1 | third party advisory exploit |
https://github.com/alextselegidis/easyappointments/commit/7f37350fab9d729a9350d96369ff0f453cf7b840 | patch |