PoC Index

CVE-2018-5385

HIGH 8.8EPSS 4.2%

Navarino Infinity is prone to session fixation attacks. The server accepts the session ID as a GET parameter which can lead to bypassing the two factor authentication in some installations. This could lead to phishing attacks that can bypass the two factor authentication that is present in some installations.

CVSS v3.0
8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
4.18% chance of exploitation in the next 30 days, 90th percentile
Published
2018-07-24
Updated
2024-08-05

Proof-of-concept exploits (1)

References

Related