CVE-2020-36948

VestaCP 0.9.8-26 contains a session token vulnerability in the LoginAs module that allows remote attackers to manipulate authentication tokens. Attackers can exploit insufficient token validation to access user accounts and perform unauthorized login requests without proper administrative permissions.
Configurations

No configuration.

History

No history.

Information

Published : 2026-01-27 16:16

Updated : 2026-01-29 16:31


NVD link : CVE-2020-36948

Mitre link : CVE-2020-36948

CVE.ORG link : CVE-2020-36948


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization