Insufficient Session Expiration in firefly-iii/firefly-iii
CVE-2023-1788
9.8CRITICAL
What is CVE-2023-1788?
The vulnerability in Firefly III stems from insufficient session expiration management. This flaw could potentially allow unauthorized users to maintain active sessions beyond their intended expiration period, posing a significant risk to data security. Users are advised to update to version 6 or later to mitigate this issue and ensure their sessions expire as expected, preventing unauthorized access.
Affected Version(s)
firefly-iii/firefly-iii < 6
