CVE-2018-10813

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
05/06/2018
Last modified:
20/07/2018

Description

In Dedos-web 1.0, the cookie and session secrets used in the Express.js application have hardcoded values that are visible in the source code published on GitHub. An attacker can edit the contents of the session cookie and re-sign it using the hardcoded secret. Due to the use of Passport.js, this could lead to privilege escalation.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:aprendecondedos:dedos-web:1.0:*:*:*:*:*:*:*