PT-2026-79297 · WordPress · Welcart E-Commerce
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Welcart e-Commerce versions prior to 2.12.1
Description
This issue occurs because the software fails to regenerate the session identifier during authentication and accepts a session identifier provided via a user-supplied request parameter. This allows an unauthenticated attacker to perform session fixation, which involves pre-setting a user's session ID, enabling the attacker to take over a customer account once the victim authenticates through a specially crafted request. The vulnerable parameter is
uscesid.Recommendations
Update to version 2.12.1 or later.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Welcart E-Commerce