Skip to content

CVE-2013-7302

Session fixation vulnerability in the Ubercart module 6.x-2.x before 6.x-2.13 and 7.x-3.x before 7.x-3.6 for Drupal, when the "Log in new customers after checkout" option is enabled, allows remote attackers to hijack web sessions by leveraging knowledge of the original session ID.

Ver en NVD

Severidad

N/A

EPSS

Probabilidad de explotación (próx. 30 días): 0.0041 (0.4%)
Percentil: 61.4%
EPSS: 2026-05-06

Afecta

ubercart:ubercartdrupal:drupal

Descripción técnica

Session fixation vulnerability in the Ubercart module 6.x-2.x before 6.x-2.13 and 7.x-3.x before 7.x-3.6 for Drupal, when the "Log in new customers after checkout" option is enabled, allows remote attackers to hijack web sessions by leveraging knowledge of the original session ID.

Publicada: 29/4/2014, 14:38:49
Última modificación: 6/5/2026, 22:30:45

Referencias

InicioEventosBlogRecursosEquipo