Back to search
CVE-2024-25977
Published: May 29, 2024
Modified: Feb 13, 2025
PUBLISHED
Description
The application does not change the session token when using the login or logout functionality. An attacker can set a session token in the victim's browser (e.g. via XSS) and prompt the victim to log in (e.g. via a redirect to the login page). This results in the victim's account being taken over.
| Vendor | Product | Versions |
|---|---|---|
Interaction Design Team at the University of Applied Sciences and Arts in Hildesheim/Germany | HAWKI | affected versions before commit 146967f |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now