SB2022032025 - Security restrictions bypass in Admidio
Published: March 20, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Weak password requirements (CVE-ID: N/A)
The vulnerability allows an attacker to compromise the affected account.
The vulnerability exists due to an error in the password change functionality, which did not reset all user's session after password change. An attacker who compromised user's session can retain access to the victim's account even after password change.
Remediation
Install update from vendor's website.