CVE-2018-10813

HIGH

Dedos-web 1.0 - Use of Hard-coded Credentials in Express.js Session Secrets

Title source: llm
STIX 2.1

Description

In Dedos-web 1.0, the cookie and session secrets used in the Express.js application have hardcoded values that are visible in the source code published on GitHub. An attacker can edit the contents of the session cookie and re-sign it using the hardcoded secret. Due to the use of Passport.js, this could lead to privilege escalation.

References (2)

Core 2
Core References
Issue Tracking, Third Party Advisory x_refsource_misc
https://github.com/aprendecondedos/dedos-web/pull/1

Scores

CVSS v3 7.3
EPSS 0.0113
EPSS Percentile 62.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-798
Status published
Products (1)
aprendecondedos/dedos-web 1.0
Published Jun 05, 2018
Tracked Since Feb 18, 2026