CVE-2020-35358

CRITICAL

DomainMOD 4.15.0 - Insufficient Session Expiration

Title source: llm
STIX 2.1

Description

DomainMOD domainmod-v4.15.0 is affected by an insufficient session expiration vulnerability. On changing a password, both sessions using the changed password and old sessions in any other browser or device do not expire and remain active. Such flaws frequently give attackers unauthorized access to some system data or functionality.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://gist.github.com/anku-agar/0fec2ffd98308e550ce9b5d4b395d0d7

Scores

CVSS v3 9.8
EPSS 0.0243
EPSS Percentile 82.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-613
Status published
Products (1)
domainmod/domainmod 4.15.0
Published Mar 15, 2021
Tracked Since Feb 18, 2026