Insufficient Session Expiration in GitHub repository answerdev/answer prior to 1.0.6.
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
Link | Tags |
---|---|
https://huntr.dev/bounties/f82388d6-dfc3-4fbc-bea6-eb40cf5b2683 | patch third party advisory exploit |
https://github.com/answerdev/answer/commit/cd742b75605c99776f32d271c0a60e0f468e181c | patch |