6.9 Medium
AI Score
Confidence
Low
0.012 Low
EPSS
Percentile
84.9%
The Chatroom Module before 4.7.x.-1.0 for Drupal broadcasts Chatroom visitorsβ session IDs to all participants, which allows remote attackers to hijack sessions and gain privileges.
drupal.org/node/102614
secunia.com/advisories/23343
www.vupen.com/english/advisories/2006/4942