Lucene search

K
osvGoogleOSV:CVE-2021-31745
HistoryDec 10, 2021 - 6:15 p.m.

CVE-2021-31745

2021-12-1018:15:07
Google
osv.dev
4

6.9 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

58.7%

Session Fixation vulnerability in login.php in Pluck-CMS Pluck 4.7.15 allows an attacker to sustain unauthorized access to the platform. Because Pluck does not invalidate prior sessions after a password change, access can be sustained even after an administrator performs regular remediation attempts such as resetting their password.

6.9 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

58.7%

Related for OSV:CVE-2021-31745