CVE-2020-18701: Critical severity lin-cms-flask vulnerability
Incorrect Access Control in Lin-CMS-Flask v0.1.1 allows remote attackers to obtain sensitive information and/or gain privileges due to the application not invalidating a user's authentication token upon logout, which allows for replaying packets.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-18701?
CVE-2020-18701 is classified as a high severity vulnerability due to its potential for unauthorized access and privilege escalation.
How do I fix CVE-2020-18701?
To fix CVE-2020-18701, ensure that the application invalidates user authentication tokens upon logout to prevent replay attacks.
What specific vulnerability does CVE-2020-18701 describe?
CVE-2020-18701 describes an incorrect access control issue that allows remote attackers to gain unauthorized access by replaying authentication tokens.
Which software versions are affected by CVE-2020-18701?
CVE-2020-18701 affects Lin-CMS-Flask version 0.1.1.
What are the consequences of exploiting CVE-2020-18701?
Exploiting CVE-2020-18701 can lead to sensitive information disclosure and unauthorized privilege escalation.