All-Dynamics Software enlogic:show 2.0.2 contains a session fixation vulnerability that allows attackers to set a predefined PHP session identifier during the login process. Attackers can forge HTTP GET requests to welcome.php with a manipulated session token to bypass authentication and potentially execute cross-site request forgery attacks.
CVSS v4.0 Metrics
Exploitability
Attack VectorNetwork
ComplexityLow
RequirementsNone
PrivilegesNone
User InteractionActive
Threat
Exploit MaturityUnreported
Vulnerable System
ConfidentialityHigh
IntegrityHigh
AvailabilityNone
Subsequent System
ConfidentialityNone
IntegrityNone
AvailabilityNone
Supplemental
SafetyNegligible
AutomatableYes
RecoveryAutomatic
Value DensityConcentrated
UrgencyMedium
Change Log
| Date | Source | Changes | Score |
|---|
| 2026-07-21 | cve.org | initial, patch: Unavailable | 6.0 |
Affected Software
| Vendor | Product | Version |
|---|
| All-Dynamics Software | enlogic:show Digital Signage System | 2.0.2 (Build 2098) ILP32W 0/1/3/1597919619 |
Published: 2026-01-06