Impact
An insufficient session expiration flaw in bizwell xClick permits an attacker to bypass authentication controls, enabling unauthorized access to protected resources or data. The vulnerability allows session tokens to remain valid beyond the intended period, creating a window for attack. The impact is an authentication bypass, giving the attacker unauthorized privilege.
Affected Systems
The flaw affects bizwell xClick releases R2, R3, and R3.1. All installations of these versions are susceptible unless mitigated by a vendor update or configuration change.
Risk and Exploitability
The CVSS score of 8.7 reflects high severity, and an EPSS score of under 1% indicates a low but non‑zero likelihood of exploitation. Because the vulnerability is not listed in CISA's KEV catalog, no prioritized exploit data is currently available. Attackers could exploit the flaw remotely via the web interface by reusing stale session tokens, so environments with insufficient session invalidation are at greatest risk.
OpenCVE Enrichment