Due to improper JSON Web Tokens implementation an unauthenticated remote attacker can guess a valid session ID and therefore impersonate a user to gain full access.
2025-04-24T10:15:16.703
2025-04-29T13:52:47.470
Awaiting Analysis
CVSSv3.1: 8.1 (HIGH)
-