The session.lua library in CGILua 5.1.x uses the same ID for each session, which allows remote attackers to hijack arbitrary sessions.…
mitre·CWE-384·Published 2020-02-06