Vulnerability Details CVE-2025-15578
Maypole versions from 2.10 through 2.13 for Perl generates session ids insecurely. The session id is seeded with the system time (which is available from HTTP response headers), a call to the built-in rand() function, and the PID.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 17.8%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2025-15578
-
cpe:2.3:a:teejay:maypole:2.10
-
cpe:2.3:a:teejay:maypole:2.11
-
cpe:2.3:a:teejay:maypole:2.111
-
cpe:2.3:a:teejay:maypole:2.12
-
cpe:2.3:a:teejay:maypole:2.121
-
cpe:2.3:a:teejay:maypole:2.13