PT-2008-2976 · Plone Foundation · Plone Cms
Adrian Pastor
+2
·
Published
2008-03-20
·
Updated
2018-10-11
·
CVE-2008-1395
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Plone CMS (affected versions not specified)
Description
The issue concerns the handling of user authentication states. Specifically, it does not record users' authentication states and implements the logout feature solely on the client side. This makes it easier for context-dependent attackers to reuse a logged-out session.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Plone Cms