PT-2025-6251 · Concorde · Concorde

Published

2025-02-11

·

Updated

2025-02-11

·

CVE-2025-24973

CVSS v3.1

9.3

Critical

VectorAV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Concorde versions prior to 12.25Q1.1
Description: The issue arises from an improper implementation of the logout process, causing authentication credentials to remain in cookies even after a user has explicitly logged out. This may allow an attacker to steal authentication tokens, potentially having devastating consequences if a user with admin privileges is or was using a shared device.
Recommendations: For versions prior to 12.25Q1.1, update to version 12.25Q1.1 to fix the issue. As a temporary workaround, clear cookies and site data in the browser after logging out. Users who have logged in on a shared device should go to Settings > Security and regenerate their login tokens.

Exploit

Fix

Insufficient Session Expiration

Weakness Enumeration

Related Identifiers

CVE-2025-24973
GHSA-2369-P2WH-7CC2

Affected Products

Concorde