Fiche vulnérabilité
CVE-2020-5224 : faille élevée django-user-sessions project… (CVSS 8.8)
Description
In Django User Sessions (django-user-sessions) before 1.7.1, the views provided allow users to terminate specific sessions. The session key is used to identify sessions, and thus included in the rendered HTML. In itself this is not a problem. However if the website has an XSS vulnerability, the session key could be extracted by the attacker and a session takeover could happen.
En bref
- Sévérité
- Élevée (CVSS 8.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 24 janv. 2020
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- django-user-sessions project django-user-sessions