ZeroHour

CVE-2022-44007

PoC
CVSS 3.1
8.8 high
EPSS
<1%p56
Published
()
Modified
Description

An issue was discovered in BACKCLICK Professional 5.9.63. Due to an unsafe implementation of session tracking, it is possible for an attacker to trick users into opening an authenticated user session for a session identifier known to the attacker, aka Session Fixation.

Vendors
backclick
Products
backclick
Weakness
CWE-384
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.