Vulnerability Description
cskefu v7 suffers from Insufficient Session Expiration, which allows attackers to exploit the old session for malicious activity.
CVSS Score
4.3
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Related Weaknesses (CWE)
References
- https://gist.github.com/menghaining/8d424faebfe869c80eadaea12bbdd158
- https://github.com/cskefu/cskefu/issues/781
- https://github.com/cskefu/cskefu/pull/803
- https://gist.github.com/menghaining/8d424faebfe869c80eadaea12bbdd158
- https://github.com/cskefu/cskefu/issues/781
- https://github.com/cskefu/cskefu/pull/803
FAQ
What is CVE-2024-29402?
CVE-2024-29402 is a vulnerability with a CVSS score of 4.3 (MEDIUM). cskefu v7 suffers from Insufficient Session Expiration, which allows attackers to exploit the old session for malicious activity.
How severe is CVE-2024-29402?
CVE-2024-29402 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-29402?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.