Description
Insufficient Session Expiration (CWE-613) in the Web Admin Panel in AxxonSoft Axxon One (C-Werk) prior to 2.0.3 on Windows allows a local or remote authenticated attacker to retain access with removed privileges via continued use of an unexpired session token until natural expiration.
Problem types
CWE-613 Insufficient Session Expiration
Product status
Any version
Credits
Discovered internally during access control regression testing.
References
www.axxonsoft.com/...y-disclosure-policy/security-advisories