PT-2026-94249 · Cjbi+1 · Admin3
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
admin3 version 3.0.0
Description
User session tokens are persisted in the audit log event body during the publishing of UserLoggedIn domain events. An attacker with
log:view permission can access these tokens by reading the JSON response from the 'GET /logs' endpoint. These harvested tokens can then be replayed as bearer credentials to gain full unauthorized access to user accounts.Recommendations
Update admin3 to a version newer than 3.0.0.
Restrict the
log:view permission to minimize the risk of session token exposure.Exploit
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Admin3