craftcms/cms is vulnerable to Session Fixation
61
Medium Risk
Affected versions of this package are vulnerable to potential session leakage, as requests might be processed after the user session has been established. This timing issue may allow unauthorized parties to intercept or reuse active sessions under certain conditions, increasing the risk of session hijacking or unauthorized access. Proper session handling should ensure that session establishment and validation occur before any sensitive request processing takes place.
You are affected if you are using a version which is within vulnerability ranges
craftcms/cms is vulnerable to Session Fixation in versions 4.0.0 - 4.16.7 and 5.0.0 - 5.8.10.
Upgrade the craftcms/cms library to a patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant