PT-2020-7599 · Cgilua · Cgilua

Felipe Daragon

·

Published

2020-02-06

·

Updated

2020-02-11

·

CVE-2014-10400

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions CGILua versions 5.0.x
Description The session.lua library uses sequential session IDs, making it easier for remote attackers to predict the session ID and hijack arbitrary sessions.
Recommendations For CGILua versions 5.0.x, consider implementing a secure random session ID generation mechanism to prevent session hijacking. As a temporary workaround, consider regenerating session IDs at regular intervals to minimize the risk of exploitation.

Fix

Session Fixation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-10400

Affected Products

Cgilua