Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mjjp-hj57-wv6f

Опубликовано: 31 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 does not properly invalidate active user sessions after a password change. This allows an attacker with a valid session token to maintain access to the account even after the legitimate user changes their password.

Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 does not properly invalidate active user sessions after a password change. This allows an attacker with a valid session token to maintain access to the account even after the legitimate user changes their password.

EPSS

Процентиль: 18%
0.00057
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-286

Связанные уязвимости

CVSS3: 6.5
nvd
3 месяца назад

Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 does not properly invalidate active user sessions after a password change. This allows an attacker with a valid session token to maintain access to the account even after the legitimate user changes their password.

EPSS

Процентиль: 18%
0.00057
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-286