Description
Camaleon CMS 0.1.7 to 2.6.0 doesn’t terminate the active session of the users, even after the admin changes the user’s password. A user that was already logged in, will still have access to the application even after the password was changed.
No analysis available yet.
Remediation
Vendor Solution
Update to 2.6.0.1
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-2278 | Camaleon CMS 0.1.7 to 2.6.0 doesn’t terminate the active session of the users, even after the admin changes the user’s password. A user that was already logged in, will still have access to the application even after the password was changed. |
Github GHSA |
GHSA-438x-2p9v-g8h9 | Camaleon CMS Insufficient Session Expiration vulnerability |
References
History
Wed, 30 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Mend
Published:
Updated: 2025-04-30T15:53:18.740Z
Reserved: 2021-01-22T00:00:00.000Z
Link: CVE-2021-25970
Updated: 2024-08-03T20:19:19.297Z
Status : Modified
Published: 2021-10-20T12:15:07.587
Modified: 2024-11-21T05:55:42.110
Link: CVE-2021-25970
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA