Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Session Fixation OVE-20230524-0004.
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Vasion_print | Printerlogic | * | 20.0.1923 (excluding) |
Virtual_appliance | Printerlogic | * | 22.0.843 (excluding) |
Such a scenario is commonly observed when: