PT-2024-24139 · Unknown · Reportico Web
Aashiqahamedno
·
Published
2024-05-14
·
Updated
2024-07-03
·
CVE-2024-31556
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Reportico Web versions prior to 8.1.0
Description
The issue allows a local attacker to execute arbitrary code and obtain sensitive information via the
sessionid function. This vulnerability arises from the failure of the web application to properly invalidate session cookies upon logout, allowing an attacker to exploit the active session cookie and perform unauthorized actions.Recommendations
For versions prior to 8.1.0, update to version 8.1.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the
sessionid function until a patch is available. Additionally, ensure that session cookies are properly invalidated upon logout to minimize the risk of exploitation.Fix
Improper Privilege Management
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Reportico Web