CVE-2023-6144

Publication date

2023-11-20 23:20:38

Family

Fluid Attacks

State

PUBLISHED

Description

Dev blog v1.0 allows to exploit an account takeover through the "user" cookie. With this, an attacker can access any users session just by knowing their username.