CVE-2021-25992
10.02.2022, 10:15
In Ifme, versions 1.0.0 to v.7.33.2 dont properly invalidate a users session even after the user initiated logout. It makes it possible for an attacker to reuse the admin cookies either via local/network access or by other hypothetical attacks.Enginsight
Vendor | Product | Version |
---|---|---|
if-me | ifme | 1.0.0 ≤ 𝑥 ≤ 7.33.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References