CVE-2024-28144

CVSS V2 None CVSS V3 None
Description
An attacker who can spoof the IP address and the User-Agent of a logged-in user can takeover the session because of flaws in the self-developed session management. If two users access the web interface from the same IP they are logged in as the other user.
Overview
  • CVE ID
  • CVE-2024-28144
  • Assigner
  • SEC-VLab
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-12-12T13:24:16.685Z
  • Last Modified Date
  • 2024-12-12T13:24:16.685Z
References
History
Created Old Value New Value Data Type Notes
2024-12-13 13:21:20 Added to TrackCVE