CVE 5.4 MEDIUM

Improper Session Cleanup on Role Removal in Web Admin Panel in AxxonSoft Axxon One_CVE-2025-10223

5.4 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Description

Insufficient Session Expiration (CWE-613) in the Web Admin Panel in AxxonSoft Axxon One prior to 2.0.3 on Windows allows a local or remote authenticated attacker to retain access with removed privileges via continued use of an unexpired session token until natural expiration.

Basic Information

ID CVE-2025-10223
Source AxxonSoft
Published Sep 10, 2025 at 12:35
Modified Sep 10, 2025 at 13:24

Affected Product

Vendor AxxonSoft
Product AxxonOne
Affected Versions AxxonSoft AxxonOne 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.