Skip to main content

Session Fixation

CVE-2022-4231

Severity Medium
Score 5.4/10

Summary

A vulnerability, which was classified as problematic, has been found in Tribal Systems Zenario CMS. This issue affects some unknown processing of the component "Remember Me Handler". The manipulation leads to session fixation. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The issue effects the versions prior to 9.3.57709.

  • LOW
  • NETWORK
  • LOW
  • UNCHANGED
  • REQUIRED
  • NONE
  • LOW
  • NONE

CWE-384 - Session Fixation

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

Advisory Timeline

  • Published