CVE-2009-10007
CRITICALDescription
Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks. Catalyst::Plugin::Authentication does not automatically change the session id after authentication. An attacker that obtains a session id cookie can use this to impersonate the victim.
Is your site exposed to CVE-2009-10007?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
References
Other References
Frequently Asked Questions
What is CVE-2009-10007? +
How severe is CVE-2009-10007? +
How do I check if I'm vulnerable to CVE-2009-10007? +
Related Vulnerabilities
This vulnerability exists in Meon KYC solutions due to improper handling of access and refresh tokens in certain API endpoints …
Session Fixation vulnerability in team-alembic ash_authentication allows an attacker who can plant a session identifier in a victim's browser to …
A Session Fixation vulnerability existed in Payload's SQLite adapter due to identifier reuse during account creation. A malicious attacker could …
Affected versions of Flowintel do not revoke existing authenticated sessions when a user’s password is changed. This means that if …
tirreno, a security framework, has a session fixation issue in versions prior to 0.10.0. During authentication, tirreno validates the user's …
A malicious actor can fix the session of a PAM user by tricking the user to click on a specially …