Launch Week Day 1: Announcing Security Design Review
UNKNOWN PyPI

CVE-2020-18701

PYSEC-2021-341 · CVE-2020-18701

Published · Modified

Description

Incorrect Access Control in Lin-CMS-Flask v0.1.1 allows remote attackers to obtain sensitive information and/or gain privileges due to the application not invalidating a user's authentication token upon logout, which allows for replaying packets.

Ready to move

Start Securing

Free, no credit card | First findings in minutes