← Back to CVE List

CVE-2024-25977

Published: 2024-05-29T13:15Z
Last Modified: 2024-11-21T20:15Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The application does not change the session token when using the login or logout functionality. An attacker can set a session token in the victim's browser (e.g. via XSS) and prompt the victim to log in (e.g. via a redirect to the login page). This results in the victim's account being taken over. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt