Description
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 is open to a session fixation attack which allows remote attackers to hijack a victim's session.
Remediation
References
Related Vulnerabilities
WordPress Plugin XO Event Calendar Cross-Site Scripting (2.3.6)
PrestaShop Improper Restriction of Rendered UI Layers or Frames Vulnerability (CVE-2018-7491)
TYPO3 Improper Input Validation Vulnerability (CVE-2020-15099)
WordPress Plugin Rimons Twitter Widget Cross-Site Scripting (1.2.4)
PostgreSQL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-5288)