CVE-2020-11728
—CVSS 3.1
7.5 high
EPSS
2%p74
Published
()
Modified
Description
An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60. Session management does not use a sufficiently hard-to-guess session key. Anyone who can guess the microsecond time (and the incrementing session_id) can impersonate a session.
In the news0 stories
No ingested article mentions this CVE yet.