VYPR

CWE-613

Insufficient Session Expiration

BaseIncomplete

Description

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (608)

page 1 of 31
  • CVE-2014-2595CriFeb 12, 2020
    risk 0.68cvss 9.8epss 0.17

    Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a permanent authentication token obtained from a query string.

  • CVE-2020-27422CriNov 16, 2020
    risk 0.67cvss 9.8epss 0.08

    In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the same link to takeover the account.

  • CVE-2024-8888CriSep 18, 2024
    risk 0.65cvss 10.0epss 0.00

    An attacker with access to the network where CIRCUTOR Q-SMT is located in its firmware version 1.0.4, could steal the tokens used on the web, since these have no expiration date to access the web application without restrictions. Token theft can originate from different methods…

  • CVE-2025-59786CriMar 4, 2026
    risk 0.64cvss 9.8epss 0.00

    2N Access Commander version 3.4.2 and prior improperly invalidates session tokens, allowing multiple session cookies to remain active after logout in web application.

  • CVE-2026-26342CriFeb 24, 2026
    risk 0.64cvss 9.8epss 0.01

    Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior implement an authentication token (X-User-Token) with insufficient expiration. An attacker who obtains a valid token (for example via interception, log exposure, or token reuse on a shared…

  • CVE-2026-1435CriFeb 18, 2026
    risk 0.64cvss 9.8epss 0.00

    Not properly invalidated session vulnerability in Graylog Web Interface, version 2.2.3, due to incorrect management of session invalidation after new logins. The application generates a new 'sessionId' each time a user authenticates, but does not invalidate previously issued…

  • CVE-2024-13996CriOct 30, 2025
    risk 0.64cvss 9.8epss 0.01

    Nagios XI versions prior to 2024R1.1.3 did not invalidate all other active sessions for a user when that user's password was changed. As a result, any pre-existing sessions (including those potentially controlled by an attacker) remained valid after a credential update. This…

  • CVE-2025-53826CriJul 15, 2025
    risk 0.64cvss 9.8epss 0.01

    File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename, and edit files. In version 2.39.0, File Browser’s authentication system issues long-lived JWT tokens that remain valid even after the user logs…

  • CVE-2024-13280CriJan 9, 2025
    risk 0.64cvss 9.8epss 0.00

    Insufficient Session Expiration vulnerability in Drupal Persistent Login allows Forceful Browsing.This issue affects Persistent Login: from 0.0.0 before 1.8.0, from 2.0.* before 2.2.2.

  • CVE-2024-43685CriOct 4, 2024
    risk 0.64cvss 9.8epss 0.00

    Improper Authentication vulnerability in Microchip TimeProvider 4100 (login modules) allows Session Hijacking.This issue affects TimeProvider 4100: from 1.0 before 2.4.7.

  • CVE-2024-29401CriMar 26, 2024
    risk 0.64cvss 9.8epss 0.01

    xzs-mysql 3.8 is vulnerable to Insufficient Session Expiration, which allows attackers to use the session of a deleted admin to do anything.

  • CVE-2023-35857CriJun 19, 2023
    risk 0.64cvss 9.8epss 0.01

    In Siren Investigate before 13.2.2, session keys remain active even after logging out.

  • CVE-2022-36179CriNov 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Fusiondirectory 1.3 suffers from Improper Session Handling.

  • CVE-2022-22318CriJun 20, 2022
    risk 0.64cvss 9.8epss 0.00

    IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.

  • CVE-2022-22317CriJun 20, 2022
    risk 0.64cvss 9.8epss 0.00

    IBM Curam Social Program Management 8.0.0 and 8.0.1 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 218281.

  • CVE-2021-22820CriJan 28, 2022
    risk 0.64cvss 9.8epss 0.01

    A CWE-614 Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain an unauthorized access over a hijacked session to the charger station web server even after the legitimate user account holder has changed his password. Affected Products:…

  • CVE-2020-27416CriDec 8, 2021
    risk 0.64cvss 9.8epss 0.02

    Mahavitaran android application 7.50 and prior are affected by account takeover due to improper OTP validation, allows remote attackers to control a users account.

  • CVE-2021-40849CriNov 3, 2021
    risk 0.64cvss 9.8epss 0.01

    In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, the account associated with a web services token is vulnerable to being exploited and logged into, resulting in information disclosure (at a minimum) and often escalation of privileges.

  • CVE-2021-38823CriOct 4, 2021
    risk 0.64cvss 9.8epss 0.02

    The IceHrm 30.0.0 OS website was found vulnerable to Session Management Issue. A signout from an admin account does not invalidate an admin session that is opened in a different browser.

  • CVE-2021-37333CriOct 4, 2021
    risk 0.64cvss 9.8epss 0.01

    Laravel Booking System Booking Core 2.0 is vulnerable to Session Management. A password change at sandbox.bookingcore.org/user/profile/change-password does not invalidate a session that is opened in a different browser.