← Back

CVE-2018-25160

nvd nist
Published: Feb 27, 2026Modified: Mar 18, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Exploitability: 3.9 / Impact: 2.5
Source: NVD

Description

HTTP::Session2 versions through 1.09 for Perl does not validate the format of user provided session ids, enabling code injection or other impact depending on session backend. For example, if an application uses memcached for session storage, then it may be possible for a remote attacker to inject memcached commands in the session id value.

Affected (1)

Products: Tokuhirom: Http\
1 product
Http\
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.09

References (4)

Source: 9b29abf9-4ab0-4765-b253-1875cd9b441e
Third Party Advisory
Source: 9b29abf9-4ab0-4765-b253-1875cd9b441e
ProductRelease Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory

Timeline

No history available yet.