Impact
The vulnerability allows an attacker to supply a session identifier in the URL or request variables instead of cookies. A malicious user can obtain a valid session token, send a crafted link to a victim, and replay that token after the victim authenticates. This permits the attacker to hijack the victim’s session and gain access to their account, compromising confidentiality and integrity of the victim’s data.
Affected Systems
Hubzero CMS versions up to and including 2.2.32 are affected. The product is open‑source and distributed under the hubzero CMS name. Users running these specific releases should confirm their build version and apply any available updates.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity, with no EPSS data available and the vulnerability not listed in the CISA KEV catalog. The likely attack vector is a manually crafted URL or link sent to a target user, a form of social engineering or phishing. An attacker who can distribute such a link and obtains a victim’s session ID before login can reuse the identifier to impersonate the victim after they authenticate.
OpenCVE Enrichment