vendor:
CCLeague Pro
by:
t0pP8uZz
5.5
CVSS
MEDIUM
Insecure Cookie Authentication
287
CWE
Product Name: CCLeague Pro
Affected Version From: 1.2 and prior
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2008
CCLeague Pro <= 1.2 Insecure Cookie Authentication Vulnerability
CCLeage Pro 1.2 and all prior versions suffer from multiple insecure cookie validation vulnerabilities. The script checks to see if a cookie is set and matches a value, which can be easily bypassed by creating a cookie. The session_id function returns the PHPSESSID, and if no session is created, it returns an empty string. By overwriting the PHPSESSID cookie, the authentication can be bypassed.
Mitigation:
The vendor has not been notified. To mitigate this vulnerability, users should update to a secure version of CCLeague Pro.