CVE-2020-5224 Information

Description

In Django User Sessions (django-user-sessions) before 1.7.1 the views provided allow users to terminate specific sessions. The session key is used to identify sessions and thus included in the rendered HTML. In itself this is not a problem. However if the website has an XSS vulnerability the session key could be extracted by the attacker and a session takeover could happen.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Reference

https://github.com/Bouke/django-user-sessions/security/advisories/GHSA-5fq8-3q2f-4m5g https://github.com/jazzband/django-user-sessions/commit/f0c4077e7d1436ba6d721af85cee89222ca5d2d9

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

8.8

Share on: