Session Fixation vulnerability in Oceanic Software ValeApp allows Brute Force, Session Hijacking. This issue affects ValeApp: before v2.0.0.
Session Fixation is when an attacker is able to impose a pre-known session identifier on a victim, and the application accepts it without generating a new token after login. When the user authenticates using the previously established identifier, the attacker can use the same identifier to gain access to the victim's session. The vulnerability can be further exploited to conduct Brute Force attacks on session tokens or Session Hijacking.
An attacker can fully hijack the session of an authenticated user, gaining unauthorized access to their account and data processed by the ValeApp application. Depending on the privileges of the hijacked account, it is possible to compromise the confidentiality, integrity, and availability of data.
ValeApp should be updated to version v2.0.0 or newer, in which the vulnerability has been fixed. It is also recommended to invalidate all active user sessions after implementing the update and to verify session management configuration in accordance with the manufacturer's guidelines available in the references.
Oceanicsoft ValeApp in all versions before v2.0.0.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XOceanicsoft Valeapp
APPOceanicsoft< 2.0.0
Related vulnerabilities
Przechowywanie wrażliwych danych w ciasteczku w postaci niezaszyfrowanej — Oceanic Software ValeApp
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oceanic ...
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in O...
Insertion of Sensitive Information into Log File vulnerability in Oceanic Software ValeApp allows Query System...