Insufficient Session Expiration in REDAXO - #VU153342
Published: October 6, 2026
Vulnerability details
The vulnerability allows a remote user to maintain unauthorized access to an account.
The vulnerability exists due to insufficient session expiration in the current backend session and stay-logged-in key when a backend user changes their password. A remote user can use a previously obtained session ID or stay-logged-in cookie to maintain unauthorized access to an account.
The stay-logged-in key can remain valid for up to three months.