Lucene search

K
patchstackChristopher EmersonPATCHSTACK:419AC368F1CAD33BF5DB90134EC273E3
HistoryNov 14, 2012 - 12:00 a.m.

WordPress <= 3.4.2

2012-11-1400:00:00
Christopher Emerson
patchstack.com
7

EPSS

0.002

Percentile

64.4%

The attackers can discover valid session identifiers via a brute-force attack, because this WordPress version does not invalidate a wordpress_sec session cookie upon an administrator’s logout action.

Solution

           The application should keep track of session identifiers where a user has explicitly logged out and prevent those sessions from connecting to the application.

EPSS

0.002

Percentile

64.4%

Related for PATCHSTACK:419AC368F1CAD33BF5DB90134EC273E3