CVE-2014-125048 is a critical session fixation vulnerability found in the app/controllers/oauth.js file of kassi xingwall. This flaw, identified as CWE-384, allows an attacker to fixate a user's session, potentially leading to unauthorized access. The vulnerability has a CVSS v3.1 score of 5.4 (MEDIUM), indicating a network-based attack with low complexity, requiring user interaction, and resulting in low impact to confidentiality and integrity. While critical, its EPSS score is very low, suggesting a minimal likelihood of exploitation. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage are also absent, indicating a lack of widespread attention or exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< e9f0d509e1408743048e29d9c099d36e0e1f6ae7CPE matchmatch criteria | cpe:2.3:a:kluks:xingwall:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.