The user_logout function in TikiWiki CMS/Groupware 4.x before 4.2 does not properly delete user login cookies, which allows remote attackers to gain access via cookie reuse.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Tikiwiki_cms/groupware | Tiki | 4.0 (including) | 4.0 (including) |
Tikiwiki_cms/groupware | Tiki | 4.1 (including) | 4.1 (including) |