VYPR
Unrated severityNVD Advisory· Published Jan 17, 2021· Updated Aug 3, 2024

CVE-2021-3113

CVE-2021-3113

Description

Netsia SEBA+ through 0.16.1 build 70-e669dcd7 allows remote attackers to discover session cookies via a direct /session/list/allActiveSession request. For example, the attacker can discover the admin's cookie if the admin account happens to be logged in when the allActiveSession request occurs, and can then use that cookie immediately for admin access,

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Netsia/SEBA+description
  • Netsia/SEBA+llm-create
    Range: <=0.16.1 build 70-e669dcd7

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.