CVE-2019-11018

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
08/04/2019
Last modified:
07/12/2023

Description

application\admin\controller\User.php in ThinkAdmin V4.0 does not prevent continued use of an administrator's cookie-based credentials after a password change.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:thinkadmin:thinkadmin:4.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools