Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8ff6-grvw-rmvx

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

DomainMOD domainmod-v4.15.0 is affected by an insufficient session expiration vulnerability. On changing a password, both sessions using the changed password and old sessions in any other browser or device do not expire and remain active. Such flaws frequently give attackers unauthorized access to some system data or functionality.

DomainMOD domainmod-v4.15.0 is affected by an insufficient session expiration vulnerability. On changing a password, both sessions using the changed password and old sessions in any other browser or device do not expire and remain active. Such flaws frequently give attackers unauthorized access to some system data or functionality.

EPSS

Процентиль: 81%
0.01477
Низкий

Дефекты

CWE-613

Связанные уязвимости

CVSS3: 9.8
nvd
почти 5 лет назад

DomainMOD domainmod-v4.15.0 is affected by an insufficient session expiration vulnerability. On changing a password, both sessions using the changed password and old sessions in any other browser or device do not expire and remain active. Such flaws frequently give attackers unauthorized access to some system data or functionality.

EPSS

Процентиль: 81%
0.01477
Низкий

Дефекты

CWE-613