Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-45659

Опубликовано: 17 окт. 2023
Источник: nvd
CVSS3: 3.6
CVSS3: 2.8
EPSS Низкий

Описание

Engelsystem is a shift planning system for chaos events. If a users' password is compromised and an attacker gained access to a users' account, i.e., logged in and obtained a session, an attackers' session is not terminated if the users' account password is reset. This vulnerability has been fixed in the commit dbb089315ff3d. Users are advised to update their installations. There are no known workarounds for this vulnerability.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:engelsystem:engelsystem:*:*:*:*:*:*:*:*
Версия до 2023-09-18 (исключая)

EPSS

Процентиль: 21%
0.00068
Низкий

3.6 Low

CVSS3

2.8 Low

CVSS3

Дефекты

CWE-613

EPSS

Процентиль: 21%
0.00068
Низкий

3.6 Low

CVSS3

2.8 Low

CVSS3

Дефекты

CWE-613