CVE-2018-1148
—CVSS 3.0
6.5 medium
EPSS
<1%p53
Published
()
Modified
Description
In Nessus before 7.1.0, Session Fixation exists due to insufficient session management within the application. An authenticated attacker could maintain system access due to session fixation after a user password change.
- Vendors
- tenable
- Products
- nessus
- Weakness
- CWE-384
- Vector
- CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.