6.1
CVE-2021-35046
- EPSS 0.76%
- Veröffentlicht 22.06.2021 14:15:08
- Zuletzt bearbeitet 21.11.2024 06:11:44
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
A session fixation vulnerability was discovered in Ice Hrm 29.0.0 OS which allows an attacker to hijack a valid user session via a crafted session cookie.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.76% | 0.506 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
| nvd@nist.gov | 5.8 | 8.6 | 4.9 |
AV:N/AC:M/Au:N/C:P/I:P/A:N
|
CWE-384 Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
https://github.com/xoffense/POC/blob/main/Account%20takeover%20%28Chaining%20session%20fixation%20%2B%20reflected%20Cross%20Site%20Scripting%29%20in%20ICE%20Hrm%20Version%2029.0.0.OS.md