Логотип exploitDog
bind:CVE-2019-7215
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-7215

Количество 2

Количество 2

nvd логотип

CVE-2019-7215

больше 6 лет назад

Progress Sitefinity 10.1.6536 does not invalidate session cookies upon logouts. It instead tries to overwrite the cookie in the browser, but it remains valid on the server side. This means the cookie can be reused to maintain access to the account, even if the account credentials and permissions are changed.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-74xh-52qm-qf5r

больше 3 лет назад

Progress Sitefinity 10.1.6536 does not invalidate session cookies upon logouts. It instead tries to overwrite the cookie in the browser, but it remains valid on the server side. This means the cookie can be reused to maintain access to the account, even if the account credentials and permissions are changed.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-7215

Progress Sitefinity 10.1.6536 does not invalidate session cookies upon logouts. It instead tries to overwrite the cookie in the browser, but it remains valid on the server side. This means the cookie can be reused to maintain access to the account, even if the account credentials and permissions are changed.

CVSS3: 6.5
0%
Низкий
больше 6 лет назад
github логотип
GHSA-74xh-52qm-qf5r

Progress Sitefinity 10.1.6536 does not invalidate session cookies upon logouts. It instead tries to overwrite the cookie in the browser, but it remains valid on the server side. This means the cookie can be reused to maintain access to the account, even if the account credentials and permissions are changed.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу