A privilege escalation issue was found in PHP Gurukul Hospital Management System In v.4.0 allows a remote attacker to execute arbitrary code and access sensitive information via the session token parameter.
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
Link | Tags |
---|---|
https://github.com/captain-noob | not applicable |
https://twitter.com/captain__noob | not applicable |
https://gist.github.com/captain-noob/aff11542477ddd0a92ad8b94ec75f832 | mitigation third party advisory exploit |