First published: Fri Dec 10 2021(Updated: )
Session Fixation vulnerability in login.php in Pluck-CMS Pluck 4.7.15 allows an attacker to sustain unauthorized access to the platform. Because Pluck does not invalidate prior sessions after a password change, access can be sustained even after an administrator performs regular remediation attempts such as resetting their password.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pluck CMS | =4.7.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-31745.
The severity of CVE-2021-31745 is high.
The affected software is Pluck-CMS Pluck 4.7.15.
CVE-2021-31745 allows an attacker to sustain unauthorized access to the platform by exploiting a session fixation vulnerability in login.php.
Yes, a fix for CVE-2021-31745 is available. It is recommended to update to a version of Pluck-CMS Pluck that addresses the vulnerability.