CVE-2018-10966
HIGHGamerPolls 0.4.6 - Session Hijacking via Hard-coded Secret in Passport.js
Title source: llmDescription
An issue was discovered in GamerPolls 0.4.6, related to config/environments/all.js and config/initializers/02_passport.js. An attacker can edit the Passport.js contents of the session cookie to contain the ID number of the account they wish to take over, and re-sign it using the hard coded secret.
References (3)
Core 3
Core References
Patch, Third Party Advisory x_refsource_misc
https://github.com/GamerPolls/gamerpolls.com/pull/56
Patch, Third Party Advisory x_refsource_confirm
https://github.com/GamerPolls/gamerpolls.com/blob/03ccbaf219410e0a45390d0efc12017f08a25282/config/environments/all.js#L58
Exploit, Third Party Advisory x_refsource_misc
https://www.digitalinterruption.com/single-post/2018/06/04/Are-Your-Cookies-Telling-Your-Fortune
Scores
CVSS v3
7.3
EPSS
0.0161
EPSS Percentile
72.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Details
CWE
CWE-798
Status
published
Products (1)
gamerpolls/gamerpolls
0.4.6
Published
Jun 05, 2018
Tracked Since
Feb 18, 2026