Session Cookie Validation Issue in ZendTo by Zend Technologies
CVE-2020-8986
9.8CRITICAL
What is CVE-2020-8986?
The session cookie validation mechanism in ZendTo, specifically in lib/NSSDropbox.php, mistakenly fails to effectively check for equality. This flaw enables an attacker to exploit the system by sending numerous requests, potentially gaining unauthorized administrative access.