cPanel before 82.0.15 allows API token credentials to persist after an account has been renamed or terminated (SEC-517).
According to WASC, “Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization.”
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cpanel | Cpanel | 81.9999.242 (including) | 82.0.15 (excluding) |