Beveiligingsadvies

CVE-2021-3740

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2024-11-15 10:57:09
Laatst bijgewerkt 2024-11-15 19:03:09
Toegewezen door @huntr_ai
CVSS-score 6.8
Status PUBLISHED

Beschrijving

A Session Fixation vulnerability exists in chatwoot/chatwoot versions prior to 2.4.0. The application does not invalidate existing sessions on other devices when a user changes their password, allowing old sessions to persist. This can lead to unauthorized access if an attacker has obtained a session token.