Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-74xh-52qm-qf5r

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Progress Sitefinity 10.1.6536 does not invalidate session cookies upon logouts. It instead tries to overwrite the cookie in the browser, but it remains valid on the server side. This means the cookie can be reused to maintain access to the account, even if the account credentials and permissions are changed.

Progress Sitefinity 10.1.6536 does not invalidate session cookies upon logouts. It instead tries to overwrite the cookie in the browser, but it remains valid on the server side. This means the cookie can be reused to maintain access to the account, even if the account credentials and permissions are changed.

EPSS

Процентиль: 0%
0.00007
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-613

Связанные уязвимости

CVSS3: 6.5
nvd
больше 6 лет назад

Progress Sitefinity 10.1.6536 does not invalidate session cookies upon logouts. It instead tries to overwrite the cookie in the browser, but it remains valid on the server side. This means the cookie can be reused to maintain access to the account, even if the account credentials and permissions are changed.

EPSS

Процентиль: 0%
0.00007
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-613