Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-55c7-jcxx-6jxx

Опубликовано: 04 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

In Shopizer versions 2.3.0 to 3.0.1 are vulnerable to Insufficient Session Expiration. When a password has been changed by the user or by an administrator, a user that was already logged in, will still have access to the application even after the password was changed.

In Shopizer versions 2.3.0 to 3.0.1 are vulnerable to Insufficient Session Expiration. When a password has been changed by the user or by an administrator, a user that was already logged in, will still have access to the application even after the password was changed.

EPSS

Процентиль: 54%
0.0031
Низкий

8.8 High

CVSS3

Дефекты

CWE-613

Связанные уязвимости

CVSS3: 8.8
nvd
почти 4 года назад

In Shopizer versions 2.3.0 to 3.0.1 are vulnerable to Insufficient Session Expiration. When a password has been changed by the user or by an administrator, a user that was already logged in, will still have access to the application even after the password was changed.

EPSS

Процентиль: 54%
0.0031
Низкий

8.8 High

CVSS3

Дефекты

CWE-613