SB2022032025 - Security restrictions bypass in Admidio



SB2022032025 - Security restrictions bypass in Admidio

Published: March 20, 2022

Security Bulletin ID SB2022032025
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Weak password requirements (CVE-ID: N/A)

The vulnerability allows an attacker to compromise the affected account.

The vulnerability exists due to an error in the password change functionality, which did not reset all user's session after password change. An attacker who compromised user's session can retain access to the victim's account even after password change.


Remediation

Install update from vendor's website.