Description
Dev blog v1.0 allows to exploit an account takeover through the "user" cookie. With this, an attacker can access any user's session just by knowing their username.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-58398 | Dev blog v1.0 allows to exploit an account takeover through the "user" cookie. With this, an attacker can access any user's session just by knowing their username. |
References
History
No history.
Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2024-08-02T08:21:17.568Z
Reserved: 2023-11-14T23:57:14.918Z
Link: CVE-2023-6144
No data.
Status : Modified
Published: 2023-11-21T00:15:07.353
Modified: 2024-11-21T08:43:14.430
Link: CVE-2023-6144
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD