ZeroHour

CVE-2018-10813

PoC
CVSS 3.0
7.3 high
EPSS
1%p65
Published
()
Modified
Description

In Dedos-web 1.0, the cookie and session secrets used in the Express.js application have hardcoded values that are visible in the source code published on GitHub. An attacker can edit the contents of the session cookie and re-sign it using the hardcoded secret. Due to the use of Passport.js, this could lead to privilege escalation.

Vendors
aprendecondedos
Products
dedos-web
Weakness
CWE-798
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.