Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-6144
HistoryNov 21, 2023 - 12:15 a.m.

Design/Logic Flaw

2023-11-2100:15:00
PRIOn knowledge base
www.prio-n.com
3
design flaw
logic flaw
user cookie
account takeover
session access

7.1 High

AI Score

Confidence

Low

0.0005 Low

EPSS

Percentile

17.0%

Dev blog v1.0 allows to exploit an account takeover through the β€œuser” cookie. With this, an attacker can access any user’s session just by knowing their username.

CPENameOperatorVersion
dev_blogeq1.0

7.1 High

AI Score

Confidence

Low

0.0005 Low

EPSS

Percentile

17.0%

Related for PRION:CVE-2023-6144