PT-2026-22399 · Unknown · Http::Session2

Published

2026-02-27

·

Updated

2026-03-08

·

CVE-2018-25160

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions HTTP::Session2 versions through 1.09
Description The software does not properly validate user-provided session IDs, which could allow for code injection or other impacts depending on the session backend. For example, if memcached is used for session storage, an attacker might be able to inject memcached commands within the session ID value.
Recommendations Update to a version of HTTP::Session2 greater than 1.09.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-25160

Affected Products

Http::Session2