CVE-2023-45659
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/10/2023
Last modified:
30/10/2023
Description
Engelsystem is a shift planning system for chaos events. If a users' password is compromised and an attacker gained access to a users' account, i.e., logged in and obtained a session, an attackers' session is not terminated if the users' account password is reset. This vulnerability has been fixed in the commit `dbb089315ff3d`. Users are advised to update their installations. There are no known workarounds for this vulnerability.
Impact
Base Score 3.x
2.80
Severity 3.x
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:engelsystem:engelsystem:*:*:*:*:*:*:*:* | 2023-09-18 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



