PT-2017-17131 · Dnalims · Dnalims

H00Die

+2

·

Publicado

2017-03-09

·

Atualizado

2017-08-16

·

CVE-2017-6529

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions dnaLIMS version 4-2015s13
Description An issue was discovered in dnaLIMS, where it is vulnerable to session hijacking by guessing the UID parameter.
Recommendations For dnaLIMS version 4-2015s13, consider implementing additional security measures to protect against session hijacking, such as restricting access to sensitive areas of the application or using more secure session management practices. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Insufficient Session Expiration

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-6529

Produtos afetados

Dnalims