Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Camaleon CMS - Insufficient Session Expiration after Password Change
Vulnerability Description
Camaleon CMS 0.1.7 to 2.6.0 doesn’t terminate the active session of the users, even after the admin changes the user’s password. A user that was already logged in, will still have access to the application even after the password was changed.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vulnerability Type
不充分的会话过期机制
Vulnerability Title
CamaleonCMS 代码问题漏洞
Vulnerability Description
CamaleonCMS是CamaleonCMS团队的一套基于RubyonRails的高级动态内容管理系统(CMS)。 Camaleon CMS 0.1.7 版本到 2.6.0 版本存在安全漏洞,该漏洞源于软件对于密码更改控制存在问题,即使管理员修改了用户的密码,也不会终止用户的活动会话。已经登录的用户即使密码被更改,也仍然可以访问应用程序。
CVSS Information
N/A
Vulnerability Type
N/A