https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-37504
Source: CVEAnnouncements
Source Link: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-37504
National Cyber Warfare Foundation (NCWF) |
HCL Compass is vulnerable to failure to invalidate sessions. The application does not invalidate authenticated sessions when the log out functionality is called. Â If the session identifier can be discovered, it could be replayed to the application and used to impersonate the user. https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-37504 Source: CVEAnnouncements Source Link: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-37504
|
|