PT-2026-82628 · Flowintel · Flowintel
CVSS v4.0
9.1
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Flowintel versions 3.3.0 and later
Description
Authenticated sessions are not revoked when a user changes their password. This allows an attacker with a valid session token to maintain access to the account until the session expires naturally, even after the password has been updated. The issue occurs within the
edit user core() and admin edit user core() functions, where the system fails to call invalidate user sessions(user.id) following a database update.Recommendations
Update Flowintel to a version where the
edit user core() and admin edit user core() functions explicitly invoke invalidate user sessions(user.id) upon password changes.Exploit
Fix
Session Fixation
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Flowintel