← Back

Aprendecondedos

aprendecondedos

1 CVE • 1 product

Products (1)

Click to collapse
Toggle
Dedos Web
dedos-web

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Aprendecondedos
1Dedos Web
Nov 21, 2024
Jun 5, 2018
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
In Dedos-web 1.0, the cookie and session secrets used in the Express.js application have hardcoded values that are visible in the source code published on GitHub. An attacker can edit the contents of the session cookie a...Show more
In Dedos-web 1.0, the cookie and session secrets used in the Express.js application have hardcoded values that are visible in the source code published on GitHub. An attacker can edit the contents of the session cookie and re-sign it using the hardcoded secret. Due to the use of Passport.js, this could lead to privilege escalation.Show less