Headline
CVE-2022-40293: Session fixation in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC.
The application was vulnerable to a session fixation that could be used hijack accounts.
Discovered by Edward Prior on behalf of The Missing Link Security
Vulnerability Details
The application was vulnerable to a Session Fixation vulnerability that could be leveraged to worsen Request Forgery Attacks, and in very rare cases could be used to hijack other accounts.
Affected Versions
Discovered in: 19.0
Fixed Versions
Fixed In: 19.0 minor release