Camaleon CMS Insufficient Session Expiration vulnerability
High severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Mar 9, 2023
Description
Published by the National Vulnerability Database
Oct 20, 2021
Published to the GitHub Advisory Database
May 24, 2022
Reviewed
Jan 24, 2023
Last updated
Mar 9, 2023
Camaleon CMS 0.1.7 through 2.6.0 doesn’t terminate the active session of the users, even after the admin changes the user’s password. A user that was already logged in, will still have access to the application even after the password was changed. Resolved in commit
77e31bc6cdde7c951fba104aebcd5ebb3f02b030
which is included in the2.6.0.1
release.References