Description
lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta failed to properly check for equality when validating the session cookie, allowing an attacker to gain administrative access with a large number of requests.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-29816 | lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta failed to properly check for equality when validating the session cookie, allowing an attacker to gain administrative access with a large number of requests. |
References
| Link | Providers |
|---|---|
| https://zend.to/changelog.php |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T10:19:19.814Z
Reserved: 2020-02-13T00:00:00.000Z
Link: CVE-2020-8986
No data.
Status : Modified
Published: 2020-03-24T21:15:15.550
Modified: 2024-11-21T05:39:46.957
Link: CVE-2020-8986
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD