Описание
Camaleon CMS 0.1.7 to 2.6.0 doesn’t terminate the active session of the users, even after the admin changes the user’s password. A user that was already logged in, will still have access to the application even after the password was changed.
Ссылки
- PatchThird Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 0.1.7 (включая) до 2.6.0 (включая)
cpe:2.3:a:tuzitio:camaleon_cms:*:*:*:*:*:*:*:*
EPSS
Процентиль: 72%
0.00702
Низкий
8.8 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-613
CWE-613
Связанные уязвимости
CVSS3: 8.8
github
больше 3 лет назад
Camaleon CMS Insufficient Session Expiration vulnerability
EPSS
Процентиль: 72%
0.00702
Низкий
8.8 High
CVSS3
6.8 Medium
CVSS2
Дефекты
CWE-613
CWE-613