CVE-2021-3113
Summary
| CVE | CVE-2021-3113 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-01-17 03:15:00 UTC |
| Updated | 2022-06-28 14:11:00 UTC |
| Description | Netsia SEBA+ through 0.16.1 build 70-e669dcd7 allows remote attackers to discover session cookies via a direct /session/list/allActiveSession request. For example, the attacker can discover the admin's cookie if the admin account happens to be logged in when the allActiveSession request occurs, and can then use that cookie immediately for admin access, |
Risk And Classification
Problem Types: CWE-425
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Pentest Blog - Self-Improvement to Ethical Hacking | MISC | www.pentest.com.tr | Exploit, Third Party Advisory |
| Netsia SEBA+ 0.16.1 - Authentication Bypass and Add Root User (Metasploit) - Multiple webapps Exploit | MISC | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| This domain is for sale at Domaincollection.com | MISC | www.netsia.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.