Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29926
HistoryApr 07, 2021 - 6:00 a.m.

Insecure Session Management

2021-04-0706:00:07
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10
insecure session
session management
mediawiki/core
security concerns
compromised tokens

EPSS

0.007

Percentile

80.1%

mediawiki/core uses an insecure session management. The unavailability of the Special:ResetTokens function causes security concerns such that if a blocked user is not able to block the use of a token that has been compromised,