Access Control Issue in Lin-CMS-Flask Product by TaleLin
CVE-2020-18701
9.8CRITICAL
What is CVE-2020-18701?
An access control vulnerability exists in Lin-CMS-Flask v0.1.1, allowing remote attackers to exploit the failure to invalidate a user's authentication token upon logout. This oversight potentially permits unauthorized access to sensitive information or privileges, as it allows attackers to replay authentication tokens. Proper measures should be implemented to ensure that user sessions are securely terminated, preventing any unauthorized access.
