CVE-2021-25970
20.10.2021, 12:15
Camaleon CMS 0.1.7 to 2.6.0 doesnt terminate the active session of the users, even after the admin changes the users password. A user that was already logged in, will still have access to the application even after the password was changed.Enginsight
Vendor | Product | Version |
---|---|---|
tuzitio | camaleon_cms | 0.1.7 ≤ 𝑥 ≤ 2.6.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References