Session Fixation
CVE-2022-4231
Summary
A vulnerability, which was classified as problematic, has been found in Tribal Systems Zenario CMS. This issue affects some unknown processing of the component "Remember Me Handler". The manipulation leads to session fixation. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The issue effects the versions prior to 9.3.57709.
- LOW
- NETWORK
- LOW
- UNCHANGED
- REQUIRED
- NONE
- LOW
- NONE
CWE-384 - Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
References
Advisory Timeline
- Published