Описание
Insufficient Session Expiration (CWE-613) in the Web Admin Panel in AxxonSoft Axxon One (C-Werk) prior to 2.0.3 on Windows allows a local or remote authenticated attacker to retain access with removed privileges via continued use of an unexpired session token until natural expiration.
Уязвимые конфигурации
Конфигурация 1Версия до 2.0.2 (включая)
cpe:2.3:a:axxonsoft:axxon_one:*:*:*:*:*:windows:*:*
EPSS
Процентиль: 12%
0.0004
Низкий
5.4 Medium
CVSS3
8.1 High
CVSS3
Дефекты
CWE-613
Связанные уязвимости
CVSS3: 5.4
github
5 месяцев назад
Insufficient Session Expiration (CWE-613) in the Web Admin Panel in AxxonSoft Axxon One prior to 2.0.3 on Windows allows a local or remote authenticated attacker to retain access with removed privileges via continued use of an unexpired session token until natural expiration.
EPSS
Процентиль: 12%
0.0004
Низкий
5.4 Medium
CVSS3
8.1 High
CVSS3
Дефекты
CWE-613