CVE-2018-10966 describes a critical vulnerability in GamerPolls 0.4.6, stemming from the use of a hardcoded secret within its Passport.js configuration. Attackers can leverage this weakness to manipulate session cookies, impersonating other users by altering the session cookie's ID and re-signing it with the known secret. This vulnerability carries a CVSS score of 7.3 (HIGH), indicating a network-based attack with low complexity, allowing for potential compromise of confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the presence of a hardcoded secret makes this a significant security flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.4.6CPE matchmatch criteria | cpe:2.3:a:gamerpolls:gamerpolls:0.4.6:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.