CVE-2018-5385 Vulnerability Details

  /     /     /  

CVE-2018-5385 Metadata Quick Info

CVE Published: 24/07/2018 | CVE Updated: 05/08/2024 | CVE Year: 2018
Source: certcc | Vendor: Navarino | Product: Infinity
Status : PUBLISHED

CVE-2018-5385 Description

Navarino Infinity is prone to session fixation attacks. The server accepts the session ID as a GET parameter which can lead to bypassing the two factor authentication in some installations. This could lead to phishing attacks that can bypass the two factor authentication that is present in some installations.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-384
CWE Name: CWE-384
Source: Navarino

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).