First published: Mon Nov 09 2020(Updated: )
Microweber 1.1.18 is affected by broken authentication and session management. Local session hijacking may occur, which could result in unauthorized access to system data or functionality, or a complete system compromise.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microweber WHMCS | =1.1.18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-23139 is a high severity vulnerability due to its potential for local session hijacking and unauthorized access.
To fix CVE-2020-23139, upgrade Microweber to a patched version that addresses the broken authentication and session management.
Exploitation of CVE-2020-23139 can lead to unauthorized access to system data or functionality and potentially a complete system compromise.
CVE-2020-23139 affects users of Microweber version 1.1.18.
Temporary workarounds for CVE-2020-23139 may involve restricting user access or implementing additional authentication measures until an upgrade can be performed.