CVE-2023-3192: Session Fixation in froxlor/froxlor
Session Fixation in GitHub repository froxlor/froxlor prior to 2.1.0.
Other sources
Versions of froxlor/froxlor prior to release 2.1.0 did not regenerate session ids appropriately which may result in session fixation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/froxlor/froxlorto a version that resolves this vulnerability.Fixed in 2.1.0 - Upgrade
Upgrade
froxlor/froxlorto a version that resolves this vulnerability.Fixed in 2.1.0
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-3192.
What is the severity of CVE-2023-3192?
The severity of CVE-2023-3192 is medium.
What is the affected software of CVE-2023-3192?
The affected software of CVE-2023-3192 is Froxlor Froxlor version up to exclusive 2.1.0.
How can I fix CVE-2023-3192?
To fix CVE-2023-3192, update Froxlor Froxlor to version 2.1.0 or later.
Where can I find more information about CVE-2023-3192?
You can find more information about CVE-2023-3192 in the following references: [GitHub Commit](https://github.com/froxlor/froxlor/commit/94d9c3eedf31bc8447e3aa349e32880dde02ee52), [Huntr Security Advisory](https://huntr.dev/bounties/f3644772-9c86-4f55-a0fa-aeb11f411551).