Incorrect cookie session handling in WombatDialer before 25.02 results in the full session identity being written to system logs and could be used by a malicious attacker to impersonate an existing user session.
References
Link | Resource |
---|---|
https://www.wombatdialer.com/blog/blog/2025/02/18/CVE/ |
Configurations
No configuration.
History
18 Feb 2025, 22:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
CWE | CWE-613 |
18 Feb 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-18 19:15
Updated : 2025-02-18 22:15
NVD link : CVE-2024-57056
Mitre link : CVE-2024-57056
CVE.ORG link : CVE-2024-57056
JSON object : View
Products Affected
No product.
CWE
CWE-613
Insufficient Session Expiration