CVE-2020-24713: High severity gophish vulnerability
Published Oct 28, 2020
·Updated
Gophish through 0.10.1 does not invalidate the gophish cookie upon logout.
Affected Software
1 affected component
Getgophish Gophish<=0.10.1
Event History
Oct 28, 2020
CVE Published
via MITRE·07:33 PM
Data Sourced
via MITRE·07:33 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-24713?
CVE-2020-24713 is classified as a medium severity vulnerability.
2
How do I fix CVE-2020-24713?
To fix CVE-2020-24713, upgrade Gophish to a version higher than 0.10.1.
3
What is the impact of CVE-2020-24713?
The impact of CVE-2020-24713 is that user sessions may remain active even after logout, potentially allowing unauthorized access.
4
How does CVE-2020-24713 affect Gophish users?
CVE-2020-24713 can affect Gophish users by not invalidating session cookies upon logout.
5
Is CVE-2020-24713 still exploitable in newer versions of Gophish?
CVE-2020-24713 is not exploitable in versions of Gophish released after 0.10.1.