The "action" get_sess_id in the web application of Pydio through 8.2.2 discloses the session cookie value in the response body, enabling scripts to get access to its value. This identifier can be reused by an attacker to impersonate a user and perform actions on behalf of him/her (if the session is still active).
References
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2019-05-31T21:09:15

Updated: 2024-08-04T22:10:09.159Z

Reserved: 2019-03-25T00:00:00

Link: CVE-2019-10045

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-05-31T22:29:00.957

Modified: 2019-06-03T13:14:13.193

Link: CVE-2019-10045

cve-icon Redhat

No data.