Beveiligingsadvies

CVE-2022-23063

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2022-05-03 08:55:09
Laatst bijgewerkt 2024-09-16 19:09:20
Toegewezen door Mend
CVSS-score 8.8
Status PUBLISHED

Beschrijving

In Shopizer versions 2.3.0 to 3.0.1 are vulnerable to Insufficient Session Expiration. When a password has been changed by the user or by an administrator, a user that was already logged in, will still have access to the application even after the password was changed.