Session Hijacking Vulnerability in Drupal's Chatroom Module
CVE-2006-6528

Currently unrated

Key Information:

Vendor
Drupal
Vendor
CVE Published:
14 December 2006

Summary

The Chatroom Module for Drupal, prior to version 4.7.x-1.0, is compromised by a vulnerability that reveals session IDs of all visitors to participants in chatrooms. This flaw allows malicious actors to initiate session hijacking attacks, enabling them to impersonate legitimate users and gain unauthorized access to their accounts, compromising user data and security.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.