Mailcow through 2024-11b has a session fixation...
High severity
Unreviewed
Published
Jan 29, 2025
to the GitHub Advisory Database
•
Updated Jan 29, 2025
Description
Published by the National Vulnerability Database
Jan 28, 2025
Published to the GitHub Advisory Database
Jan 29, 2025
Last updated
Jan 29, 2025
Mailcow through 2024-11b has a session fixation vulnerability in the web panel. It allows remote attackers to set a session identifier when HSTS is disabled on a victim's browser. After a user logs in, they are authenticated and the session identifier is valid. Then, a remote attacker can access the victim's web panel with the same session identifier.
References