PT-2020-7598 · Cgilua · Cgilua

Published

2020-02-06

·

Updated

2020-02-11

·

CVE-2014-10399

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions CGILua versions 5.1.x
Description The session.lua library uses the same ID for each session, allowing remote attackers to hijack arbitrary sessions.
Recommendations For CGILua versions 5.1.x, consider implementing a unique session ID generation mechanism to prevent session hijacking. As a temporary workaround, restrict access to sensitive areas of the application to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Session Fixation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-10399

Affected Products

Cgilua