ZeroHour

CVE-2025-15578

CVSS 3.1
9.8 critical
EPSS
<1%p20
Published
()
Modified
Description

Maypole versions from 2.10 through 2.13 for Perl generates session ids insecurely. The session id is seeded with the system time (which is available from HTTP response headers), a call to the built-in rand() function, and the PID.

Vendors
teejay
Products
maypole
Weakness
CWE-338
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.