CVE-2024-25977

CVSS V2 None CVSS V3 None
Description
The application does not change the session token when using the login or logout functionality. An attacker can set a session token in the victim's browser (e.g. via XSS) and prompt the victim to log in (e.g. via a redirect to the login page). This results in the victim's account being taken over.
Overview
  • CVE ID
  • CVE-2024-25977
  • Assigner
  • SEC-VLab
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-05-29T12:31:29.973Z
  • Last Modified Date
  • 2024-06-13T20:39:22.943Z
History
Created Old Value New Value Data Type Notes
2024-06-26 12:28:58 Added to TrackCVE