HUBzero CMS(版本 2.2.32 及以下)存在一个会话固定漏洞:该CMS不仅从 Cookie 中读取会话标识符,还接受通过查询字符串(query string)和请求变量传递的会话标识符。这使得未认证的 attackers(攻击者)可以固定受害者的会话。攻击者可以先获取一个有效的会话标识符,然后向受害者发送一个包含该标识符的构造链接;当受害者通过该链接访问并成功认证后,攻击者可以重放(replay)该标识符,从而劫持受害者的账户和访问权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| hubzero | hubzero-cms | 0 ~ 2.2.32 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet