CVE-2023-45659

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/10/2023
Last modified:
30/10/2023

Description

Engelsystem is a shift planning system for chaos events. If a users' password is compromised and an attacker gained access to a users' account, i.e., logged in and obtained a session, an attackers' session is not terminated if the users' account password is reset. This vulnerability has been fixed in the commit `dbb089315ff3d`. Users are advised to update their installations. There are no known workarounds for this vulnerability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:engelsystem:engelsystem:*:*:*:*:*:*:*:* 2023-09-18 (excluding)