CVE-2014-10400: Keplerproject Cgilua

Medium severity, CVSS 6.1. EPSS: 1.2% chance of exploitation in the next 30 days.

The session.lua library in CGILua 5.0.x uses sequential session IDs, which makes it easier for remote attackers to predict the session ID and hijack arbitrary sessions. NOTE: this vulnerability was SPLIT from CVE-2014-2875.

Affected products

  • Keplerproject Cgilua: from 5.0.0, up to and including 5.0.1; from 5.1.0, up to and including 5.1.4; version 5.2 only

Published 2020-02-06. Last modified 2026-06-17.