Skip to content

Autologin cookie accessible by scripts

Moderate
trasher published GHSA-hwxq-4c5f-m4v2 Sep 15, 2021

Package

No package listed

Affected versions

< 9.5.6

Patched versions

9.5.6

Description

Impact

Cookie used to store the autologin cookie (when a user uses the "remember me" feature) is accessible by scripts. A malicious plugin that would steal this cookie would be able to use it to autologin.

Patches

TODO

Workarounds

Not using the "remember me" feature.

References

https://huntr.dev/bounties/b2e99a41-b904-419f-a274-ae383e4925f2/

Severity

Moderate

CVE ID

CVE-2021-39210

Weaknesses

Credits