CVE-2019-8149
Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to
Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An unauthenticated user can append arbitrary session id that will not be invalidated by subsequent authentication.
CRITICAL · CVSS 9.8
EPSS 0.00424
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0