PT-2024-24139 · Unknown · Reportico Web

Aashiqahamedno

·

Published

2024-05-14

·

Updated

2024-07-03

·

CVE-2024-31556

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Reportico Web versions prior to 8.1.0
Description The issue allows a local attacker to execute arbitrary code and obtain sensitive information via the sessionid function. This vulnerability arises from the failure of the web application to properly invalidate session cookies upon logout, allowing an attacker to exploit the active session cookie and perform unauthorized actions.
Recommendations For versions prior to 8.1.0, update to version 8.1.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the sessionid function until a patch is available. Additionally, ensure that session cookies are properly invalidated upon logout to minimize the risk of exploitation.

Fix

Improper Privilege Management

Insufficient Session Expiration

Weakness Enumeration

Related Identifiers

CVE-2024-31556
GHSA-2Q2F-H83X-CX3X

Affected Products

Reportico Web