Vulnerabilities > CVE-2021-37333 - Insufficient Session Expiration vulnerability in Bookingcore Booking Core 2.0

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
bookingcore
CWE-613
critical

Summary

Laravel Booking System Booking Core 2.0 is vulnerable to Session Management. A password change at sandbox.bookingcore.org/user/profile/change-password does not invalidate a session that is opened in a different browser.

Vulnerable Configurations

Part Description Count
Application
Bookingcore
1

Common Weakness Enumeration (CWE)