Lucene search

K
osvGoogleOSV:CVE-2018-18380
HistoryOct 19, 2018 - 8:29 p.m.

CVE-2018-18380

2018-10-1920:29:00
Google
osv.dev
3

AI Score

7.1

Confidence

Low

EPSS

0.001

Percentile

42.0%

A Session Fixation issue was discovered in Bigtree before 4.2.24. admin.php accepts a user-provided PHP session ID instead of regenerating a new one after a user has logged in to the application. The Session Fixation could allow an attacker to hijack an admin session.

AI Score

7.1

Confidence

Low

EPSS

0.001

Percentile

42.0%

Related for OSV:CVE-2018-18380