VYPR
Medium severity5.4NVD Advisory· Published May 27, 2021· Updated Jun 17, 2026

CVE-2021-33394

CVE-2021-33394

Description

Cubecart 6.4.2 allows Session Fixation. The application does not generate a new session cookie after the user is logged in. A malicious user is able to create a new session cookie value and inject it to a victim. After the victim logs in, the injected cookie becomes valid, giving the attacker access to the user's account through the active session.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Cubecart/Cubecart2 versions
    cpe:2.3:a:cubecart:cubecart:6.4.2:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:cubecart:cubecart:6.4.2:*:*:*:*:*:*:*
    • (no CPE)range: 6.4.2

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.