First published: Sun Apr 23 2017(Updated: )
Invision Power Services (IPS) Community Suite before 4.1.9 makes session hijack easier by relying on the PHP uniqid function without the more_entropy flag. Attackers can guess an Invision Power Board session cookie if they can predict the exact time of cookie generation.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Invision Community | <=4.1.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2564 has been classified as a medium severity vulnerability due to its potential for session hijacking.
To fix CVE-2016-2564, upgrade your Invision Power Board to version 4.1.9 or later where the vulnerability has been addressed.
CVE-2016-2564 enables session hijacking by allowing attackers to predict and guess session cookies.
CVE-2016-2564 affects all versions of Invision Power Board before 4.1.9.
CVE-2016-2564 is caused by the use of the PHP uniqid function without the more_entropy flag, making session cookie generation predictable.