An issue in youdiancms v.9.5.20 and before allows a remote attacker to escalate privileges via the sessionID parameter in the index.php file.
The vulnerability classified as CWE-384 (Session Fixation) consists of improper validation of the sessionID parameter passed to the index.php file. An attacker can manipulate the value of this parameter in a way that allows hijacking or fixing the session of a privileged user. Since the attack does not require authentication or victim interaction, it can be performed entirely remotely over the network.
Successful exploitation of the vulnerability allows an attacker to escalate privileges to a privileged user or administrator level, which may result in complete takeover of the application, disclosure of sensitive data, and modification or deletion of website content.
Apply patches available from the vendor according to references. Additionally, it is recommended to restrict access to the index.php file from external networks and implement mechanisms for monitoring suspicious requests containing unexpected sessionID parameter values.
YouDianCMS version 9.5.20 and all earlier versions.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HYoudiancms
APPYoudiancms≤ 9.5.20
Related vulnerabilities
SQL injection w YoudianCMS v9.5.0 poprzez parametr IdList
YoudianCMS v9.5.0 was discovered to contain a SQL injection vulnerability via the MailSendID parameter at /App...
YoudianCMS v9.5.0 was discovered to contain a SQL injection vulnerability via the id parameter at /App/Lib/Act...
A lack of filtering for searched keywords in the search bar of YouDianCMS 8.0 allows attackers to perform SQL ...
A vulnerability classified as problematic has been found in YouDianCMS 9.5.21. This affects an unknown part of...