ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-35591”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-35591
Published
2021-02-18
CVSS:
5.4
ShadowTrackr CVSS:
0.5
Summary:
Pi-hole 5.0, 5.1, and 5.1.1 allows Session Fixation. The application does not generate a new session cookie after the user is logged in. A malicious user is able to create a new session cookie value and inject it to a victim. After the victim logs in, the injected cookie becomes valid, giving the attacker access to the user's account through the active session.