CRITICAL🇵🇱 Wersja polska

CVE-2024-57052

CVSS 9.8v3.1pub. 2025-01-27upd. 2025-06-27

An issue in youdiancms v.9.5.20 and before allows a remote attacker to escalate privileges via the sessionID parameter in the index.php file.

🤖 AI Analysis
How it works

The vulnerability classified as CWE-384 (Session Fixation) consists of improper validation of the sessionID parameter passed to the index.php file. An attacker can manipulate the value of this parameter in a way that allows hijacking or fixing the session of a privileged user. Since the attack does not require authentication or victim interaction, it can be performed entirely remotely over the network.

Impact

Successful exploitation of the vulnerability allows an attacker to escalate privileges to a privileged user or administrator level, which may result in complete takeover of the application, disclosure of sensitive data, and modification or deletion of website content.

Mitigation & patch

Apply patches available from the vendor according to references. Additionally, it is recommended to restrict access to the index.php file from external networks and implement mechanisms for monitoring suspicious requests containing unexpected sessionID parameter values.

Who is affected

YouDianCMS version 9.5.20 and all earlier versions.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Youdiancms

    APP
    Youdiancms
    ≤ 9.5.20
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
LPE
CWE
References

Related vulnerabilities

CVE-2022-32301CRITICAL9.8PL ✓same product

SQL injection w YoudianCMS v9.5.0 poprzez parametr IdList

CVE-2022-32300HIGH8.8same product

YoudianCMS v9.5.0 was discovered to contain a SQL injection vulnerability via the MailSendID parameter at /App...

CVE-2022-32299HIGH8.8same product

YoudianCMS v9.5.0 was discovered to contain a SQL injection vulnerability via the id parameter at /App/Lib/Act...

CVE-2020-18116HIGH8.8same product

A lack of filtering for searched keywords in the search bar of YouDianCMS 8.0 allows attackers to perform SQL ...

CVE-2025-3531MEDIUM5.3same product

A vulnerability classified as problematic has been found in YouDianCMS 9.5.21. This affects an unknown part of...