PT-2020-20409 · Zend · Zendto

Published

2020-03-24

·

Updated

2020-03-27

·

CVE-2020-8986

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ZendTo versions prior to 5.22-2 Beta
Description The issue is related to the lib/NSSDropbox.php file in ZendTo, where it failed to properly check for equality when validating the session cookie. This allows an attacker to gain administrative access with a large number of requests.
Recommendations For versions prior to 5.22-2 Beta, update to version 5.22-2 Beta or later to resolve the issue. As a temporary workaround, consider restricting access to administrative functions until the update is applied.

Fix

Improper Check for Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-8986

Affected Products

Zendto