CVE-2020-1501824.06.2020, 13:15playSMS through 1.4.3 is vulnerable to session fixation.EnginsightProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVectorNISTNIST6.5 MEDIUMNETWORKLOWNONECVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:NmitreCNA------CVEADP------Base ScoreCVSS 3.xEPSS ScorePercentile: 42%VendorProductVersionplaysmsplaysms𝑥≤ 1.4.3𝑥= Vulnerable software versionsKnown Exploits!https://github.com/antonraharja/playSMS/issues/605https://github.com/antonraharja/playSMS/issues/605Common Weakness EnumerationCWE-384 - Session FixationAuthenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.Referenceshttps://github.com/antonraharja/playSMS/issues/605https://github.com/antonraharja/playSMS/issues/605