vendor:
WorldServer
by:
RedTeam Pentesting
5.3
CVSS
MEDIUM
Session Token Enumeration
CWE
Product Name: WorldServer
Affected Version From: 11.7.3 and earlier versions
Affected Version To:
Patch Exists: YES
Related CWE: CVE-2023-38357
CPE:
Platforms Tested:
2023
RWS WorldServer 11.7.3 – Session Token Enumeration
Session tokens in RWS WorldServer have a low entropy and can be enumerated, leading to unauthorised access to user sessions.
Mitigation:
Upgrade to fixed version 11.8.0