PT-2024-21048 · Alf.Io · Alf.Io

Lujiefsi

·

Published

2024-02-16

·

Updated

2024-12-18

·

CVE-2024-25628

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions Alf.io versions prior to 2.0-M4-2402
Description Alf.io is a free and open source event attendance management system. The issue allows users to access the admin area even after being invalidated or deleted. There are no known workarounds for this issue. All users are advised to upgrade to version 2.0-M4-2402 to address this issue.
Recommendations For versions prior to 2.0-M4-2402, upgrade to version 2.0-M4-2402 to resolve the issue. As a temporary workaround, consider restricting access to the admin area until the upgrade is applied.

Exploit

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-25628
GHSA-8P6M-MM22-Q893

Affected Products

Alf.Io