Back to search
CVE-2018-5385
Published: Jul 24, 2018
Modified: Aug 5, 2024
PUBLISHED
Description
Navarino Infinity is prone to session fixation attacks. The server accepts the session ID as a GET parameter which can lead to bypassing the two factor authentication in some installations. This could lead to phishing attacks that can bypass the two factor authentication that is present in some installations.
| Vendor | Product | Versions |
|---|---|---|
Navarino | Infinity | affected 2.2 - < 2.2 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now