PT-2023-29633 · Unknown · Engelsystem
Sev-Hack
·
Publicado
2023-10-16
·
Atualizado
2023-10-30
·
CVE-2023-45659
CVSS v3.1
3.6
Baixa
| Vetor | AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Engelsystem (affected versions not specified)
Description
Engelsystem is a shift planning system for chaos events. If a user's password is compromised and an attacker gains access to the user's account, the attacker's session is not terminated if the user's account password is reset.
Recommendations
Update installations to a version that includes the fix committed in
dbb089315ff3d.
As a temporary workaround, consider implementing additional security measures to monitor and terminate suspicious sessions.
Restrict access to sensitive areas of the system until the update is applied.
There are no known workarounds for this issue, so updating is the recommended course of action.Exploit
Correção
Insufficient Session Expiration
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Engelsystem