Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Time of check to time of use vulnerability in ponzu cms #339

Open
Loginsoft-Research opened this issue Mar 3, 2020 · 0 comments
Open

Time of check to time of use vulnerability in ponzu cms #339

Loginsoft-Research opened this issue Mar 3, 2020 · 0 comments

Comments

@Loginsoft-Research
Copy link

Vulnerability Description :- The Ponzu CMS is vulnerable to TOCTTOU attack. When an admin user deletes another admin user in the web application who is logged in at another system’s browser. After deleting, deleted admin user’s session will be active and he can perform any action in the web application, although his account is deleted.

Step To Reproduce :-

Create an admin user.
Log in at another system’s browser.
Delete that user.
User session will be active.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant