PT-2022-27080 · Unknown · Simmeth Lieferantenmanager
Steffen Robertz
·
Published
2022-12-25
·
Updated
2023-01-05
·
CVE-2022-44017
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Simmeth Lieferantenmanager versions prior to 5.6
Description
An issue was discovered due to errors in session management, allowing an attacker to log back into a victim's account after the victim logged out. The "/LMS/LM/#main" endpoint can be used for this. This is due to the credentials not being cleaned from the local storage after logout.
Recommendations
For versions prior to 5.6, update to version 5.6 or later to resolve the issue. As a temporary workaround, consider clearing the local storage after logout to prevent unauthorized access. Restrict access to the "/LMS/LM/#main" endpoint until the issue is resolved.
Exploit
Fix
Session Fixation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simmeth Lieferantenmanager