Discovered by Edward Prior on behalf of The Missing Link Security
The application was vulnerable to a Session Fixation vulnerability that could be leveraged to worsen Request Forgery Attacks, and in very rare cases could be used to hijack other accounts.
Discovered in: 19.0
Fixed In: 19.0 minor release