PT-2024-21048 · Alf.Io · Alf.Io
Lujiefsi
·
Published
2024-02-16
·
Updated
2024-12-18
·
CVE-2024-25628
CVSS v3.1
7.6
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
Alf.io versions prior to 2.0-M4-2402
Description
Alf.io is a free and open source event attendance management system. The issue allows users to access the admin area even after being invalidated or deleted. There are no known workarounds for this issue. All users are advised to upgrade to version 2.0-M4-2402 to address this issue.
Recommendations
For versions prior to 2.0-M4-2402, upgrade to version 2.0-M4-2402 to resolve the issue. As a temporary workaround, consider restricting access to the admin area until the upgrade is applied.
Exploit
Fix
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alf.Io