Lucene search

K
hackeroneUnknownH1:1168192
HistoryJul 12, 2018 - 12:00 a.m.

Versa Networks: Session Fixation Exposure

2018-07-1200:00:00
Unknown
hackerone.com
8

0.001 Low

EPSS

Percentile

42.8%

In VOS user session identifier (authentication token) is issued to the browser prior to authentication but is not changed after the user successfully logs into the application. Failing to issue a new session ID following a successful login introduces the possibility for an attacker to set up a trap session on the device the victim is likely to login with.

0.001 Low

EPSS

Percentile

42.8%

Related for H1:1168192