exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

FusionPBX Session Fixation

FusionPBX Session Fixation
Posted Mar 28, 2024
Authored by Yogesh Bhandage

FusionPBX suffers from a session fixation vulnerability.

tags | exploit
SHA-256 | 80babf076c9e7398fb72180f2da01bce706e004dd86503ce23c6645034cb5d21

FusionPBX Session Fixation

Change Mirror Download
*Vulnerability Name - *Application is Vulnerable to Session Fixation

*Vulnerable URL: *www.fusionpbx.com


*Overview of the Vulnerability*
Session fixation is a security vulnerability that occurs when an attacker
sets or fixes a user's session identifier, manipulating the authentication
process. Typically exploited in web applications, this vulnerability allows
the attacker to force a user's session ID to a known value, granting
unauthorized access. Attackers can initiate the attack by tricking users
into using a provided session ID or by planting a session ID through
various means.


*Steps to Reproduce*
Step 1: To reproduce this vulnerability open two browsers. Copy "PHPSESSID"
cookie from Browser 1 and paste it to Browser 2.
Step 2: Login in Browser 1 using valid credentials.
Step 3: Navigate to Browser 2 and refresh the page or open this URL (
https://www.fusionpbx.com/app/account/home.php)
Step 4: Successfully logged in Browser 2 without entering the credentials.


*Impact of Vulnerability:*
Anyone can easily hijack victims or user's sessions and get into his account
. Cookie stealing is the best way the hacker can get into account.. it
would not take more than 5 min to steal someone's cookie using PHP and all
.....
Even friends can fool the victim and get him hacked...


*Mitigation:*Manage sessions properly. This problem is mainly faced because
the session doesn't get expired or doesn't get closed when logout is
pressed. Each time the user logins the cookie must hold a unique different
session-id to proceed.


------------------------------------------------------------------------------------------------------


*FusionPBX Development Team Implemented Fix GitHub Commit Links:*
https://github.com/fusionpbx/fusionpbx/commit/50220d7a0674fae944a1e16fab7a8517cdc51a9e
https://github.com/fusionpbx/fusionpbx/commit/560a51cff710df12c863de53c4c8289e1516dae8

Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    23 Files
  • 25
    Apr 25th
    16 Files
  • 26
    Apr 26th
    14 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close