PT-2026-22399 · Unknown · Http::Session2
Published
2026-02-27
·
Updated
2026-03-08
·
CVE-2018-25160
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
HTTP::Session2 versions through 1.09
Description
The software does not properly validate user-provided session IDs, which could allow for code injection or other impacts depending on the session backend. For example, if memcached is used for session storage, an attacker might be able to inject memcached commands within the session ID value.
Recommendations
Update to a version of HTTP::Session2 greater than 1.09.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Http::Session2