Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38014
HistoryNov 16, 2022 - 4:07 a.m.

Insecure Session Management

2022-11-1604:07:39
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
19
concrete cms
vulnerability
session management
genericoauthtypecontroller.php
oauth
authentication

0.001 Low

EPSS

Percentile

46.8%

Concrete CMS is vulnerable to insecure sessions management. The vulnerability exists in the attemptAuthentication function in GenericOauthTypeController.php where it does not issue a new session ID upon successful OAuth authentication.

0.001 Low

EPSS

Percentile

46.8%

Related for VERACODE:38014