Skip to main content

CVE detail

CVE-2014-6028

TorrentFlux 2.4 allows remote authenticated users to obtain other users' cookies via the cid parameter in an editCookies action to profile.php.

CVSS 4.0 · Medium