CVE-2021-25970
EUVD-2022-227820.10.2021, 12:15
Camaleon CMS 0.1.7 to 2.6.0 doesn’t terminate the active session of the users, even after the admin changes the user’s password. A user that was already logged in, will still have access to the application even after the password was changed.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| tuzitio | camaleon_cms | 0.1.7 ≤ 𝑥 ≤ 2.6.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References