ZeroHour

CVE-2023-6144

PoC
CVSS 3.1
4.8 medium
EPSS
<1%p38
Published
()
Modified
Description

Dev blog v1.0 allows to exploit an account takeover through the "user" cookie. With this, an attacker can access any user's session just by knowing their username.

Vendors
armanidrisi
Products
dev blog
Weakness
CWE-639
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.