First published: Wed Oct 28 2020(Updated: )
A Weak Session Management vulnerability in Citadel WebCit through 926 allows unauthenticated remote attackers to hijack recently logged-in users' sessions. NOTE: this was reported to the vendor in a publicly archived "Multiple Security Vulnerabilities in WebCit 926" thread.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Citadel WebCit | <=926 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27739 is a Weak Session Management vulnerability in Citadel WebCit through version 926.
CVE-2020-27739 allows unauthenticated remote attackers to hijack recently logged-in users' sessions in Citadel WebCit.
The severity of CVE-2020-27739 is critical with a CVSS score of 9.8.
To fix CVE-2020-27739, it is recommended to upgrade Citadel WebCit to a version beyond 926.
You can find more information about CVE-2020-27739 on the Citadel website and in the publicly archived "Multiple Security Vulnerabilities in WebCit 926" thread.