Insufficient Session Expiration in forkcms/forkcms


Reported on

Oct 14th 2021


Insufficient Session expiration even after Credential like password of the account is being updated.

Proof of Concept

  • open the same account in multiple browsers.
  • change the password in one Browser.
  • Reload the other one.
  • as a result we can see the account on the other browser is not being logged out.


The session persists even after password change

We have contacted a member of the forkcms team and are waiting to hear back 2 years ago
Jelmer Prins validated this vulnerability 2 years ago
Ajmal Aboobacker has been awarded the disclosure bounty
The fix bounty is now up for grabs
Jelmer Prins
a year ago


fix is currently in review

Jelmer Prins marked this as fixed in 5.11.1 with commit 7003a3 a year ago
Jelmer Prins has been awarded the fix bounty
This vulnerability will not receive a CVE
to join this conversation