In RedpwnCTF before version 2.3, there is a session fixation vulnerability in exploitable through the `#token=$ssid` hash when making a…
GitHub_M·CWE-384·Published 2020-04-01