A CWE-613 “Insufficient Session Expiration” vulnerability in the web application, due to the session cookie “sessionid” lasting two weeks, facilitates session hijacking attacks against victims. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.
This Cyber News was published on www.tenable.com. Publication date: Tue, 05 Mar 2024 13:11:04 +0000