Description
Session Fixation vulnerability in login.php in Pluck-CMS Pluck 4.7.15 allows an attacker to sustain unauthorized access to the platform. Because Pluck does not invalidate prior sessions after a password change, access can be sustained even after an administrator performs regular remediation attempts such as resetting their password.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-18629 | Session Fixation vulnerability in login.php in Pluck-CMS Pluck 4.7.15 allows an attacker to sustain unauthorized access to the platform. Because Pluck does not invalidate prior sessions after a password change, access can be sustained even after an administrator performs regular remediation attempts such as resetting their password. |
References
| Link | Providers |
|---|---|
| https://github.com/pluck-cms/pluck/issues/99 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T23:03:33.786Z
Reserved: 2021-04-23T00:00:00.000Z
Link: CVE-2021-31745
No data.
Status : Modified
Published: 2021-12-10T18:15:07.463
Modified: 2024-11-21T06:06:10.513
Link: CVE-2021-31745
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD