PT-2023-29633 · Unknown · Engelsystem

Sev-Hack

·

Published

2023-10-16

·

Updated

2023-10-30

·

CVE-2023-45659

CVSS v3.1

3.6

Low

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Engelsystem (affected versions not specified)
Description Engelsystem is a shift planning system for chaos events. If a user's password is compromised and an attacker gains access to the user's account, the attacker's session is not terminated if the user's account password is reset.
Recommendations Update installations to a version that includes the fix committed in dbb089315ff3d. As a temporary workaround, consider implementing additional security measures to monitor and terminate suspicious sessions. Restrict access to sensitive areas of the system until the update is applied. There are no known workarounds for this issue, so updating is the recommended course of action.

Exploit

Fix

Insufficient Session Expiration

Weakness Enumeration

Related Identifiers

CVE-2023-45659
GHSA-F6MM-3V2H-JM6X

Affected Products

Engelsystem