PT-2026-94357 · Unknown · Hubzero-Cms
CVSS v4.0
8.5
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
HUBzero CMS versions prior to 2.2.33
Description
The software accepts session identifiers from query strings and request variables instead of relying exclusively on cookies. This allows unauthenticated attackers to perform session fixation, where they obtain a valid session identifier and trick a victim into using it via a crafted link. Once the victim authenticates, the attacker can replay the identifier to hijack the account and gain unauthorized access.
Recommendations
Update HUBzero CMS to version 2.2.33 or later.
Exploit
Fix
Session Fixation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hubzero-Cms