Joomla! Core is prone to a session fixation vulnerability. An attacker may leverage this issue to hijack an arbitrary session and gain access to sensitive information, which may help in launching further attacks. Joomla! Core versions 1.5.x ranging from 1.5.0 and up to and including 1.5.15 are vulnerable.
References
Link | Resource |
---|---|
https://developer.joomla.org/security-centre/309-20100423-core-sessation-fixation.html | Vendor Advisory |
https://www.acunetix.com/vulnerabilities/web/joomla-core-1-5-x-session-fixation-1-5-0-1-5-15/ | Third Party Advisory |
Configurations
History
25 Jun 2021, 15:36
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-384 | |
CVSS |
v2 : v3 : |
v2 : 5.0
v3 : 7.5 |
CPE | cpe:2.3:a:joomla:joomla\!:*:*:*:*:*:*:*:* | |
References | (MISC) https://developer.joomla.org/security-centre/309-20100423-core-sessation-fixation.html - Vendor Advisory | |
References | (MISC) https://www.acunetix.com/vulnerabilities/web/joomla-core-1-5-x-session-fixation-1-5-0-1-5-15/ - Third Party Advisory |
21 Jun 2021, 23:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-06-21 23:15
Updated : 2024-02-04 21:47
NVD link : CVE-2010-1434
Mitre link : CVE-2010-1434
CVE.ORG link : CVE-2010-1434
JSON object : View
Products Affected
joomla
- joomla\!
CWE
CWE-384
Session Fixation