Home
MEDIUM: 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:NDefault status
unaffected
Any version before 3.17.2
affected
Description
Bludit allows user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behavior enables an attacker to fix a session ID for a victim and later hijack the authenticated session. This issue was fixed in version 3.17.2.
Problem types
Product status
Any version before 3.17.2
Credits
Arkadiusz Marta
References
cert.pl/posts/2026/03/CVE-2026-25099
github.com/bludit/bludit/releases/tag/3.17.2