vendor:
WebCit
by:
Simone Quatrini
7.5
CVSS
HIGH
Session Hijacking
613
CWE
Product Name: WebCit
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE: a:citadel:webcit:926
Platforms Tested:
Citadel WebCit < 926 - Session Hijacking Exploit
This exploit allows an attacker to hijack user sessions in Citadel WebCit version 926. It works by sending a specially crafted HTTP request with a manipulated cookie value. By exploiting this vulnerability, an attacker can impersonate a legitimate user and gain unauthorized access to the system.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a patched version of Citadel WebCit.