CVE-2021-25981
03.01.2022, 07:15
In Talkyard, regular versions v0.2021.20 through v0.2021.33 and dev versions v0.2021.20 through v0.2021.34, are vulnerable to Insufficient Session Expiration. This may allow an attacker to reuse the admins still-valid session token even when logged-out, to gain admin privileges, given the attacker is able to obtain that token (via other, hypothetical attacks)Enginsight
Vendor | Product | Version |
---|---|---|
talkyard | talkyard | 0.2021.20 ≤ 𝑥 < 0.2021.35 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References