CVE-2025-24502

An improper session validation allows an unauthenticated attacker to cause certain request notifications to be executed in the context of an incorrect user by spoofing the client IP address.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2025-01-30 19:15

Updated : 2025-02-05 05:15


NVD link : CVE-2025-24502

Mitre link : CVE-2025-24502

CVE.ORG link : CVE-2025-24502


JSON object : View

Products Affected

No product.

CWE
CWE-384

Session Fixation