CVE Vulnerabilities

CVE-2018-14387

Session Fixation

Published: Jul 18, 2018 | Modified: Sep 19, 2018
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in WonderCMS before 2.5.2. An attacker can create a new session on a web application and record the associated session identifier. The attacker then causes the victim to authenticate against the server using the same session identifier. The attacker can access the users account through the active session. The Session Fixation attack fixes a session on the victims browser, so the attack starts before the user logs in.

Weakness

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

Affected Software

Name Vendor Start Version End Version
Wondercms Wondercms * 2.5.2 (excluding)

Extended Description

Such a scenario is commonly observed when:

Potential Mitigations

References