PT-2022-27069 · Unknown · Backclick Professional

Moritz Bechler

·

Published

2022-11-16

·

Updated

2025-04-29

·

CVE-2022-44007

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BACKCLICK Professional version 5.9.63
Description An issue was discovered due to an unsafe implementation of session tracking, making it possible for an attacker to trick users into opening an authenticated user session for a session identifier known to the attacker, also known as Session Fixation.
Recommendations For BACKCLICK Professional version 5.9.63, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Session Fixation

Weakness Enumeration

Related Identifiers

CVE-2022-44007

Affected Products

Backclick Professional