Engelsystem is a shift planning system for chaos events. If a users password is compromised and an attacker gained access to a users account, i.e., logged in and obtained a session, an attackers session is not terminated if the users account password is reset. This vulnerability has been fixed in the commit dbb089315ff3d. Users are advised to update their installations. There are no known workarounds for this vulnerability.
According to WASC, “Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization.”
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Engelsystem | Engelsystem | * | 2023-09-18 (excluding) |