NA

CVE-2023-45659

Published: 17/10/2023 Updated: 30/10/2023
CVSS v3 Base Score: 2.8 | Impact Score: 1.4 | Exploitability Score: 1.3
VMScore: 0

Vulnerability Summary

Engelsystem is a shift planning system for chaos events. If a users' password is compromised and an attacker gained access to a users' account, i.e., logged in and obtained a session, an attackers' session is not terminated if the users' account password is reset. This vulnerability has been fixed in the commit `dbb089315ff3d`. Users are advised to update their installations. There are no known workarounds for this vulnerability.

Vulnerable Product Search on Vulmon Subscribe to Product

engelsystem engelsystem

Github Repositories

About me πŸ‘‹ πŸ”Ž Job title: Application Security Engineer πŸŒ‡ Current location: Moscow, Russia πŸ’₯ Certificates: OSCP (November 2021) πŸ’’ CVEs: CVE-2023-45659 CVE-2023-45152 CVE-2023-5838 CVE-2023-5840 πŸͺ Open for collaboration