CVE Feed

    Dashboard / CVE / CVE-2020-14017

    CVE-2020-14017

    An issue was discovered in Navigate CMS 2.9 r1433. Sessions, as well as associated information such as CSRF tokens, are stored in cleartext files in the directory /private/sessions. An unauthenticated user could use a brute-force approach to attempt to identify existing sessions, or view the contents of this file to discover details about a session.

    Published:Jun 24, 2020
    Last Modified:Nov 21, 2024
    EPS:Jun 24, 2020
    EPSS Score:0.00387
    CVSS Score:7.5

    Affected Products

    Vendor
    Naviwebs
    Product
    Navigate Cms

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High