Description
The cookie implementation in Vanilla Forums before 2.0.17.6 makes it easier for remote attackers to spoof signed requests, and consequently obtain access to arbitrary user accounts, via HMAC timing attacks.
Remediation
References
Related Vulnerabilities
WordPress Plugin Responsive Menu-Create Mobile-Friendly Menu Multiple Vulnerabilities (4.0.3)
WordPress Plugin DeMomentSomTres Subscribe Cross-Site Scripting (201909190900)
Oracle Application Server Other Vulnerability (CVE-2002-1630)
Joomla Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2010-1432)