If two users share access to the same client device, then a Session Fixation vulnerability enables the first user to impersonate the second user.
CiviCRM v6.12.0 and earlier (Standalone only)
CiviCRM v6.12.1, v6.10.3 (ESR), and later (Standalone only)
Upgrade to a fixed version of CiviCRM
Tim Otten (CiviCRM), Rich Lott (Artful Robot), Benjamin W
