CVE-2023-6144
CVSS V2 None
CVSS V3 None
Description
Dev blog v1.0 allows to exploit an account takeover through the "user" cookie. With this, an attacker can access any user's session just by knowing their username.
Overview
- CVE ID
- CVE-2023-6144
- Assigner
- Fluid Attacks
- Vulnerability Status
- PUBLISHED
- Published Version
- 2023-11-20T23:20:38.606Z
- Last Modified Date
- 2023-11-20T23:20:38.606Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://fluidattacks.com/advisories/almighty/ | |
https://github.com/Armanidrisi/devblog/ |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-6144 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-6144 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-25 07:11:11 | Added to TrackCVE |