PT-2023-29633 · Unknown · Engelsystem

Sev-Hack

·

Publicado

2023-10-16

·

Atualizado

2023-10-30

·

CVE-2023-45659

CVSS v3.1

3.6

Baixa

VetorAV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Engelsystem (affected versions not specified)
Description Engelsystem is a shift planning system for chaos events. If a user's password is compromised and an attacker gains access to the user's account, the attacker's session is not terminated if the user's account password is reset.
Recommendations Update installations to a version that includes the fix committed in dbb089315ff3d. As a temporary workaround, consider implementing additional security measures to monitor and terminate suspicious sessions. Restrict access to sensitive areas of the system until the update is applied. There are no known workarounds for this issue, so updating is the recommended course of action.

Exploit

Correção

Insufficient Session Expiration

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-45659
GHSA-F6MM-3V2H-JM6X

Produtos afetados

Engelsystem