Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wx4j-99r4-v8wg

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In “Orchard core CMS” application, versions 1.0.0-beta1-3383 to 1.0.0 are vulnerable to an improper session termination after password change. When a password has been changed by the user or by an administrator, a user that was already logged in, will still have access to the application even after the password was changed.

In “Orchard core CMS” application, versions 1.0.0-beta1-3383 to 1.0.0 are vulnerable to an improper session termination after password change. When a password has been changed by the user or by an administrator, a user that was already logged in, will still have access to the application even after the password was changed.

EPSS

Процентиль: 53%
0.00299
Низкий

Дефекты

CWE-613

Связанные уязвимости

CVSS3: 8.8
nvd
больше 4 лет назад

In “Orchard core CMS” application, versions 1.0.0-beta1-3383 to 1.0.0 are vulnerable to an improper session termination after password change. When a password has been changed by the user or by an administrator, a user that was already logged in, will still have access to the application even after the password was changed.

EPSS

Процентиль: 53%
0.00299
Низкий

Дефекты

CWE-613