CVE: CVE-2009-1283

Export to Word

glFusion before 1.1.3 performs authentication with a user-provided password hash instead of a password, which allows remote attackers to gain privileges by obtaining the hash and using it in the glf_password cookie, aka "User Masquerading." NOTE: this can be leveraged with a separate SQL injection vulnerability to steal hashes.

Threat-Mapped Scoring

Score: 3.0

Priority: P2 - Serious (High)

EPSS

Score: 0.01549
Percentile: 0.80599

CVSS Scoring

CVSS v2 Score: 6.8

Severity:

Affected Products

← Back to Home