60
CVE-2017-11879
—CVSS 3.0
8.8 high
EPSS
9%p95
Published
()
Modified
Description
ASP.NET Core 2.0 allows an attacker to steal log-in session information such as cookies or authentication tokens via a specially crafted URL aka "ASP.NET Core Elevation Of Privilege Vulnerability".
- Vendors
- microsoft
- Products
- asp.net core
- Weakness
- CWE-601
- Vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H