Impact
admin3 (v3.0.0 and earlier) stores user session tokens in the audit log event body when publishing UserLoggedIn events. An attacker who can read the JSON response from the GET /logs endpoint can harvest these tokens and replay them as bearer credentials, thereby gaining full access to the user account. This vulnerability directly enables unauthorized account takeover and is classified under CWE-532, a serious data disclosure flaw. The CVSS score of 8.7 categorizes it as high severity.
Affected Systems
The affected product is admin3 from the vendor cjbi, specifically all releases up through version 3.0.0. Users running any of these versions are vulnerable if they have audit logs enabled and if session tokens are logged.
Risk and Exploitability
The vulnerability is high severity (CVSS 8.7) but currently has no EPSS score available and is not listed in the CISA KEV catalog. The attack requires the attacker to possess log:view permission, which typically means internal or compromised access. Once that privilege is attained, the attacker can easily retrieve session tokens via the GET /logs endpoint and reuse them as bearer tokens to impersonate any user. The lack of exploit data suggests the exploit is feasible but may not yet be widely used. Therefore, the risk is high for organizations that grant log viewing rights broadly or do not enforce strict role separation.
OpenCVE Enrichment