Gnuboard · Gnuboard · CVE-2024-41475
**Name of the Vulnerable Software and Affected Versions**
Gnuboard g6 version 6.0.7
**Description**
The issue is related to Session hijacking due to a CORS misconfiguration. This allows for unauthorized access to user sessions.
**Recommendations**
For Gnuboard g6 version 6.0.7, update the CORS configuration to properly restrict access and prevent session hijacking. As a temporary workaround, consider restricting access to sensitive areas of the application to minimize the risk of exploitation.