PT-2021-21610 · Unknown · Laravel Booking System Booking Core

Published

2021-10-04

·

Updated

2021-10-12

·

CVE-2021-37333

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Laravel Booking System Booking Core version 2.0
Description The issue concerns session management. When a password is changed at the "/user/profile/change-password" API endpoint, it does not invalidate a session opened in a different browser.
Recommendations For Laravel Booking System Booking Core version 2.0, as a temporary workaround, consider implementing a mechanism to invalidate all active sessions when a user changes their password. Restrict access to sensitive features until the session management issue is fully resolved.

Exploit

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-37333

Affected Products

Laravel Booking System Booking Core