Insecure Permissions vulnerability in icmsdev iCMS v.7.0.16 allows a remote attacker to obtain sensitive information.
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
Link | Tags |
---|---|
https://www.icmsdev.com/ | product |
https://gist.github.com/ChubbyZ/0ddb9772231d9a8c5b5345883abcb0a6 | third party advisory |