Files
CVEs-PoC/2021/CVE-2021-25981.md
2025-09-29 21:09:30 +02:00

19 lines
1012 B
Markdown
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
### [CVE-2021-25981](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-25981)
![](https://img.shields.io/static/v1?label=Product&message=talkyard&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=unspecified%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=v0.2021.20%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-613%20Insufficient%20Session%20Expiration&color=brightgreen)
### Description
In Talkyard, regular versions v0.2021.20 through v0.2021.33 and dev versions v0.2021.20 through v0.2021.34, are vulnerable to Insufficient Session Expiration. This may allow an attacker to reuse the admins still-valid session token even when logged-out, to gain admin privileges, given the attacker is able to obtain that token (via other, hypothetical attacks)
### POC
#### Reference
- https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25981
#### Github
No PoCs found on GitHub currently.