Bludit
cpe:2.3:a:bludit:bludit:*:*:*:*:*:*:*
- < 3.17.2
A session fixation vulnerability has been identified in Bludit versions prior to 3.17.2. This issue allows an attacker to set a session identifier for a victim before authentication, with the session ID remaining unchanged after the victim logs in. As a result, the attacker can hijack the authenticated session.
Exploitation of this vulnerability allows for session hijacking, where an attacker can take over an authenticated user's session.
Users can upgrade to Bludit version 3.17.2 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.