The notification emails sent by Soar Cloud HR Portal contain a link with a embedded session. The expiration of the session is not properly configured, remaining valid for more than 7 days and can be reused.
Solution:
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
Link | Tags |
---|---|
https://www.twcert.org.tw/tw/cp-132-7871-fecf1-1.html | third party advisory |
https://www.twcert.org.tw/en/cp-139-7872-1c8b4-2.html | third party advisory |