Session Fixation in GitHub repository froxlor/froxlor prior to 2.1.0.
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
Link | Tags |
---|---|
https://huntr.dev/bounties/f3644772-9c86-4f55-a0fa-aeb11f411551 | patch third party advisory exploit |
https://github.com/froxlor/froxlor/commit/94d9c3eedf31bc8447e3aa349e32880dde02ee52 | patch |