CVE-2024-25977: Interaction Design Team At The University Of Applied Sciences And Arts In Hildesheim/germany Hawki
High severity, CVSS 7.3. EPSS: 0.6% chance of exploitation in the next 30 days.
The application does not change the session token when using the login or logout functionality. An attacker can set a session token in the victim's browser (e.g. via XSS) and prompt the victim to log in (e.g. via a redirect to the login page). This results in the victim's account being taken over.
Affected products
Published 2024-05-29. Last modified 2026-06-17.