First published: Mon Nov 09 2020(Updated: )
Microweber v1.1.18 is affected by no session expiry after log-out.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/microweber/microweber | =1.1.18 | |
Microweber WHMCS | =1.1.18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-23136 is classified as a security vulnerability due to the lack of session expiry after log-out.
To fix CVE-2020-23136, ensure that sessions are properly invalidated upon user log-out.
The risks of CVE-2020-23136 include unauthorized access to user accounts if users remain logged in after attempting to log out.
CVE-2020-23136 specifically affects Microweber version 1.1.18.
A possible workaround for CVE-2020-23136 is to manually clear cookies and session data before exiting the application.