Impact
A flaw in the login component of SourceCodester Prison Management System 1.0 permits an attacker to set a user’s session identifier before authentication. Once the user logs in, the application accepts the pre‑set identifier, allowing the attacker to impersonate the account. This session fixation can lead to unauthorized access to restricted data and actions within the system.
Affected Systems
The vulnerability affects only SourceCodester Prison Management System version 1.0, as identified by the vendor and the component name in the description. No other products or versions are listed as impacted.
Risk and Exploitability
The CVSS base score of 6.9 indicates a moderate severity. The exploit probability is reported as less than 1 % by EPSS, and the vulnerability is not included in the CISA Known Exploited Vulnerabilities catalog. Attackers can target the login page from a remote location and do not need special permissions beyond the ability to submit a request. While exploitation is considered low probability, the potential for unauthorized access warrants prompt attention.
OpenCVE Enrichment