Camaleon CMS 0.1.7 to 2.6.0 doesn’t terminate the active session of the users, even after the admin changes the user’s password. A user that was already logged in, will still have access to the application even after the password was changed.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mend

Published: 2021-10-20T11:55:16

Updated: 2024-08-03T20:19:19.297Z

Reserved: 2021-01-22T00:00:00

Link: CVE-2021-25970

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-10-20T12:15:07.587

Modified: 2021-10-29T18:40:59.727

Link: CVE-2021-25970

cve-icon Redhat

No data.