CVE-2022-44007
Summary
| CVE | CVE-2022-44007 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-11-16 22:15:00 UTC |
| Updated | 2022-11-21 18:26:00 UTC |
| Description | An issue was discovered in BACKCLICK Professional 5.9.63. Due to an unsafe implementation of session tracking, it is possible for an attacker to trick users into opening an authenticated user session for a session identifier known to the attacker, aka Session Fixation. |
Risk And Classification
Problem Types: CWE-384
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2022-036.txt | MISC | www.syss.de | |
| BACKCLICK Professional: Vielfältige Schwachstellen | MISC | www.syss.de | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.