Engelsystem is a shift planning system for chaos events. If a users password is compromised and an attacker gained access to a users account, i.e., logged in and obtained a session, an attackers session is not terminated if the users account password is reset. This vulnerability has been fixed in the commit dbb089315ff3d
. Users are advised to update their installations. There are no known workarounds for this vulnerability.
According to WASC, “Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization.”
Name | Vendor | Start Version | End Version |
---|---|---|---|
Engelsystem | Engelsystem | * | 2023-09-18 (excluding) |