Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery…
mitre·CWE-384·Published 2018-11-04