Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:33529
HistoryJan 06, 2022 - 4:17 a.m.

Insecure Session Management

2022-01-0604:17:28
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

0.001 Low

EPSS

Percentile

42.3%

shopware/shopware uses an insecure session management. The library does not invalidate session tokens after the user password change, allowing an attacker to gain access to the system if an old session token was obtained.

0.001 Low

EPSS

Percentile

42.3%

Related for VERACODE:33529