CVE-2020-5224 Information
Feb 14, 2021
cve
Description
In Django User Sessions (django-user-sessions) before 1.7.1 the views provided allow users to terminate specific sessions. The session key is used to identify sessions and thus included in the rendered HTML. In itself this is not a problem. However if the website has an XSS vulnerability the session key could be extracted by the attacker and a session takeover could happen.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
https://github.com/Bouke/django-user-sessions/security/advisories/GHSA-5fq8-3q2f-4m5g https://github.com/jazzband/django-user-sessions/commit/f0c4077e7d1436ba6d721af85cee89222ca5d2d9
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: