VYPR

Seba\+

by Netsia

CVEs (1)

  • CVE-2021-3113HigJan 17, 2021
    risk 0.49cvss 7.5epss 0.03

    Netsia SEBA+ through 0.16.1 build 70-e669dcd7 allows remote attackers to discover session cookies via a direct /session/list/allActiveSession request. For example, the attacker can discover the admin's cookie if the admin account happens to be logged in when the allActiveSession…