CVE-2018-25100 describes a cookie leakage vulnerability in the Mojolicious module for Perl, specifically affecting versions prior to 7.66. This flaw in Mojo::UserAgent::CookieJar can expose cookies under specific conditions involving multiple similar cookies for the same domain. Rated as Medium severity (CVSS 5.3), it has a low impact on integrity (I:L) with no confidentiality or availability impact, and can be exploited remotely with low attack complexity. There is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage, suggesting a low current threat landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | N/A | n/aCNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.