Session Fixation Vulnerability in Joomla! Core by Joomla
CVE-2010-1434

7.5HIGH

Key Information:

Vendor
Joomla
Status
Vendor
CVE Published:
21 June 2021

Summary

Joomla! Core is prone to a session fixation vulnerability, which allows attackers to hijack user sessions by exploiting session management flaws. This can lead to unauthorized access to sensitive user data and further exploitation of the web application. The affected versions, from 1.5.0 through 1.5.15, put users at risk if not properly mitigated. It is crucial for administrators to update their Joomla! installations and implement additional security measures to protect against unauthorized session access.

Affected Version(s)

Joomla Joomla core from 1.5.0 up to and including 1.5.15

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.