An issue was discovered in BACKCLICK Professional 5.9.63. Due to an unsafe implementation of session tracking, it is possible for an attacker to trick users into opening an authenticated user session for a session identifier known to the attacker, aka Session Fixation.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-46970 An issue was discovered in BACKCLICK Professional 5.9.63. Due to an unsafe implementation of session tracking, it is possible for an attacker to trick users into opening an authenticated user session for a session identifier known to the attacker, aka Session Fixation.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 29 Apr 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-04-29T20:31:25.154Z

Reserved: 2022-10-29T00:00:00.000Z

Link: CVE-2022-44007

cve-icon Vulnrichment

Updated: 2024-08-03T13:47:05.423Z

cve-icon NVD

Status : Modified

Published: 2022-11-16T22:15:11.177

Modified: 2025-04-29T21:15:49.783

Link: CVE-2022-44007

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.