VYPR
High severity7.5NVD Advisory· Published Jan 17, 2021· Updated Jun 17, 2026

CVE-2021-3113

CVE-2021-3113

Description

Netsia SEBA+ through 0.16.1 build 70-e669dcd7 allows remote attackers to discover session cookies via a direct /session/list/allActiveSession request. For example, the attacker can discover the admin's cookie if the admin account happens to be logged in when the allActiveSession request occurs, and can then use that cookie immediately for admin access,

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Netsia/SEBA+description
  • Netsia/Seba\+llm-fuzzy2 versions
    <=0.16.1 build 70-e669dcd7+ 1 more
    • (no CPE)range: <=0.16.1 build 70-e669dcd7
    • cpe:2.3:a:netsia:seba\+:*:*:*:*:*:*:*:*range: <=0.16.1

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.