CVE-2014-10400: Keplerproject Cgilua
Medium severity, CVSS 6.1. EPSS: 1.2% chance of exploitation in the next 30 days.
The session.lua library in CGILua 5.0.x uses sequential session IDs, which makes it easier for remote attackers to predict the session ID and hijack arbitrary sessions. NOTE: this vulnerability was SPLIT from CVE-2014-2875.
Affected products
- Keplerproject Cgilua: from 5.0.0, up to and including 5.0.1; from 5.1.0, up to and including 5.1.4; version 5.2 only
Published 2020-02-06. Last modified 2026-06-17.