Session Fixation Vulnerability in CubeCart by CubeCart Ltd.
CVE-2021-33394
5.4MEDIUM
What is CVE-2021-33394?
The CubeCart version 6.4.2 has a significant vulnerability where it fails to create a new session cookie upon user login. This allows an attacker to craft and inject a malicious session cookie prior to the target user logging in. Once the user logs in, the compromised cookie remains valid, enabling the attacker to assume the user’s identity and gain unauthorized access to their account. This vulnerability poses serious risks to user security and data integrity.
