Insufficient Session Expiration in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
Link | Tags |
---|---|
https://huntr.com/bounties/fba2991a-1b8a-4c89-9689-d708526928e1 | patch third party advisory exploit |
https://github.com/pkp/pkp-lib/commit/32d071ef2090fc336bc17d56a86d1dff90c26f0b | patch |