The user_logout function in TikiWiki CMS/Groupware 4.x before 4.2 does not properly delete user login cookies, which allows remote attackers to gain access via cookie reuse.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Tikiwiki_cms/groupware | Tiki | 4.0 (including) | 4.0 (including) |
| Tikiwiki_cms/groupware | Tiki | 4.1 (including) | 4.1 (including) |