CVE-2008-1395: High severity plone cms vulnerability
Plone CMS does not record users' authentication states, and implements the logout feature solely on the client side, which makes it easier for context-dependent attackers to reuse a logged-out session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1395?
CVE-2008-1395 has a medium severity rating due to its potential for context-dependent exploitation.
How do I fix CVE-2008-1395?
To mitigate CVE-2008-1395, ensure that user authentication states are managed on the server side instead of the client side.
What systems are affected by CVE-2008-1395?
CVE-2008-1395 affects the Plone CMS software, particularly all versions of Plone CMS.
What risks does CVE-2008-1395 pose?
CVE-2008-1395 allows attackers to reuse a logged-out session, potentially leading to unauthorized access.
Is there a patch available for CVE-2008-1395?
There is no specific patch for CVE-2008-1395, but updating to the latest version of Plone and implementing security best practices can help mitigate the vulnerability.