VYPR
Unrated severityNVD Advisory· Published Mar 20, 2008· Updated Jun 16, 2026

CVE-2008-1395

CVE-2008-1395

Description

Plone CMS does not record users' authentication states, and implements the logout feature solely on the client side, which makes it easier for context-dependent attackers to reuse a logged-out session.

Affected products

2
  • cpe:2.3:a:plone:plone_cms:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:plone:plone_cms:*:*:*:*:*:*:*:*
    • (no CPE)

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.