CWE-613
Allowed-with-ReviewInsufficient Session Expiration
Abstraction: Base · Status: Incomplete
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
1017 vulnerabilities reference this CWE, most recent first.
GHSA-XF4R-HWM6-XHX6
Vulnerability from github – Published: 2026-09-26 15:31 – Updated: 2026-09-26 15:31froxlor versions before 2.3.12 fail to invalidate existing panel sessions, API keys, and 2FA trust cookies when a user password is changed. Attackers holding hijacked sessions, valid API keys, or 2FA trust tokens retain full account access after password rotation, bypassing incident response actions.
{
"affected": [],
"aliases": [
"CVE-2026-100711"
],
"database_specific": {
"cwe_ids": [
"CWE-613"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-09-26T14:16:56Z",
"severity": "HIGH"
},
"details": "froxlor versions before 2.3.12 fail to invalidate existing panel sessions, API keys, and 2FA trust cookies when a user password is changed. Attackers holding hijacked sessions, valid API keys, or 2FA trust tokens retain full account access after password rotation, bypassing incident response actions.",
"id": "GHSA-xf4r-hwm6-xhx6",
"modified": "2026-09-26T15:31:23Z",
"published": "2026-09-26T15:31:23Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/froxlor/froxlor/security/advisories/GHSA-57wv-g7m3-hmff"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-100711"
},
{
"type": "WEB",
"url": "https://www.vulncheck.com/advisories/froxlor-before-2.3.12-authentication-bypass-via-session-persistence"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"type": "CVSS_V4"
}
]
}
GHSA-XGP8-2WW2-CMG3
Vulnerability from github – Published: 2022-05-24 19:05 – Updated: 2022-08-06 00:00Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the following: Hijack a user session Execute arbitrary commands as a root user on the underlying operating system Conduct a cross-site scripting (XSS) attack Conduct an HTML injection attack For more information about these vulnerabilities, see the Details section of this advisory.
{
"affected": [],
"aliases": [
"CVE-2021-1542"
],
"database_specific": {
"cwe_ids": [
"CWE-287",
"CWE-613"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2021-06-16T18:15:00Z",
"severity": "HIGH"
},
"details": "Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series Smart Switches could allow an attacker to do the following: Hijack a user session Execute arbitrary commands as a root user on the underlying operating system Conduct a cross-site scripting (XSS) attack Conduct an HTML injection attack For more information about these vulnerabilities, see the Details section of this advisory.",
"id": "GHSA-xgp8-2ww2-cmg3",
"modified": "2022-08-06T00:00:48Z",
"published": "2022-05-24T19:05:27Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-1542"
},
{
"type": "WEB",
"url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ciscosb-multivulns-Wwyb7s5E"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-XJ6R-WV4Q-MRM6
Vulnerability from github – Published: 2022-02-26 00:00 – Updated: 2022-03-05 00:00In JetBrains TeamCity before 2021.2, a logout action didn't remove a Remember Me cookie.
{
"affected": [],
"aliases": [
"CVE-2022-24332"
],
"database_specific": {
"cwe_ids": [
"CWE-613"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2022-02-25T15:15:00Z",
"severity": "MODERATE"
},
"details": "In JetBrains TeamCity before 2021.2, a logout action didn\u0027t remove a Remember Me cookie.",
"id": "GHSA-xj6r-wv4q-mrm6",
"modified": "2022-03-05T00:00:56Z",
"published": "2022-02-26T00:00:43Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-24332"
},
{
"type": "WEB",
"url": "https://blog.jetbrains.com"
},
{
"type": "WEB",
"url": "https://blog.jetbrains.com/blog/2022/02/08/jetbrains-security-bulletin-q4-2021"
}
],
"schema_version": "1.4.0",
"severity": []
}
GHSA-XMGH-R945-WQ5R
Vulnerability from github – Published: 2026-08-27 18:32 – Updated: 2026-08-27 18:32HCL IntelliOps Event Management (IEM) is affected by a Session Deletion Vulnerability. It may allow improper handling of user sessions, resulting in sessions not being fully terminated after logout or deletion.
{
"affected": [],
"aliases": [
"CVE-2025-62342"
],
"database_specific": {
"cwe_ids": [
"CWE-613"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-08-27T17:17:05Z",
"severity": "MODERATE"
},
"details": "HCL IntelliOps Event Management (IEM) is affected by a Session Deletion Vulnerability. It may allow improper handling of user sessions, resulting in sessions not being fully terminated after logout or deletion.",
"id": "GHSA-xmgh-r945-wq5r",
"modified": "2026-08-27T18:32:21Z",
"published": "2026-08-27T18:32:21Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-62342"
},
{
"type": "WEB",
"url": "https://support.hcl-software.com/csm?id=kb_article\u0026sysparm_article=KB0131777"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-XMP3-76FC-6JHM
Vulnerability from github – Published: 2022-02-11 00:00 – Updated: 2022-02-11 00:00In Ifme, versions 1.0.0 to v.7.33.2 don’t properly invalidate a user’s session even after the user initiated logout. It makes it possible for an attacker to reuse the admin cookies either via local/network access or by other hypothetical attacks.
{
"affected": [],
"aliases": [
"CVE-2021-25992"
],
"database_specific": {
"cwe_ids": [
"CWE-613"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2022-02-10T10:15:00Z",
"severity": "CRITICAL"
},
"details": "In Ifme, versions 1.0.0 to v.7.33.2 don\u2019t properly invalidate a user\u2019s session even after the user initiated logout. It makes it possible for an attacker to reuse the admin cookies either via local/network access or by other hypothetical attacks.",
"id": "GHSA-xmp3-76fc-6jhm",
"modified": "2022-02-11T00:00:46Z",
"published": "2022-02-11T00:00:46Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-25992"
},
{
"type": "WEB",
"url": "https://github.com/ifmeorg/ifme/commit/014f6d3526a594109d4d6607c2f30b1865e37611"
},
{
"type": "WEB",
"url": "https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25992"
}
],
"schema_version": "1.4.0",
"severity": []
}
GHSA-XPQJ-27X8-277F
Vulnerability from github – Published: 2022-05-24 16:58 – Updated: 2022-05-24 16:58NETGEAR JNR1010 devices before 1.0.0.32 have Incorrect Access Control because the ok value of the auth cookie is a special case.
{
"affected": [],
"aliases": [
"CVE-2016-11014"
],
"database_specific": {
"cwe_ids": [
"CWE-613"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2019-10-16T11:15:00Z",
"severity": "CRITICAL"
},
"details": "NETGEAR JNR1010 devices before 1.0.0.32 have Incorrect Access Control because the ok value of the auth cookie is a special case.",
"id": "GHSA-xpqj-27x8-277f",
"modified": "2022-05-24T16:58:48Z",
"published": "2022-05-24T16:58:48Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2016-11014"
},
{
"type": "WEB",
"url": "https://github.com/cybersecurityworks/Disclosed/issues/14"
},
{
"type": "WEB",
"url": "https://cybersecurityworks.com/zerodays/cve-2016-11014-netgear.html"
},
{
"type": "WEB",
"url": "https://khalil-shreateh.com/khalil.shtml/it-highlights/593-Netgear-1.0.0.24-Bypass---Improper-Session-Management--.html"
},
{
"type": "WEB",
"url": "https://lists.openwall.net/full-disclosure/2016/01/11/5"
},
{
"type": "WEB",
"url": "https://packetstormsecurity.com/files/135216/Netgear-1.0.0.24-Bypass-Improper-Session-Management.html"
}
],
"schema_version": "1.4.0",
"severity": []
}
GHSA-XQQG-X653-VRX5
Vulnerability from github – Published: 2024-01-26 21:30 – Updated: 2024-04-01 09:30A vulnerability was found in Totolink N200RE V5 9.3.5u.6255_B20211224. It has been classified as problematic. Affected is an unknown function of the file /cgi-bin/cstecgi.cgi. The manipulation leads to session expiration. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. VDB-252186 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
{
"affected": [],
"aliases": [
"CVE-2024-0942"
],
"database_specific": {
"cwe_ids": [
"CWE-613"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-26T20:15:54Z",
"severity": "LOW"
},
"details": "A vulnerability was found in Totolink N200RE V5 9.3.5u.6255_B20211224. It has been classified as problematic. Affected is an unknown function of the file /cgi-bin/cstecgi.cgi. The manipulation leads to session expiration. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. VDB-252186 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.",
"id": "GHSA-xqqg-x653-vrx5",
"modified": "2024-04-01T09:30:31Z",
"published": "2024-01-26T21:30:22Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0942"
},
{
"type": "WEB",
"url": "https://drive.google.com/file/d/1oWAGbmDtHDIUN1WSRAh4ZnuzHOuvTU4T/view?usp=sharing"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.252186"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.252186"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.269679"
},
{
"type": "WEB",
"url": "https://youtu.be/b0tU2CiLbnU"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-XQRW-V83C-FJPF
Vulnerability from github – Published: 2026-03-16 15:30 – Updated: 2026-04-20 15:31Insufficient Session Expiration in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstation to escalate their privileges via disclosure of local admin password.
{
"affected": [],
"aliases": [
"CVE-2025-15552"
],
"database_specific": {
"cwe_ids": [
"CWE-613"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-03-16T14:17:56Z",
"severity": "MODERATE"
},
"details": "Insufficient Session Expiration in Truesec\u2019s LAPSWebUI before version 2.4 allows an attacker with access to a workstation to escalate their privileges via disclosure of local admin password.",
"id": "GHSA-xqrw-v83c-fjpf",
"modified": "2026-04-20T15:31:50Z",
"published": "2026-03-16T15:30:41Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15552"
},
{
"type": "WEB",
"url": "https://labs.reversec.com/advisories/2026/03/long-session-lifetime-in-truesec-lapswebui"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"type": "CVSS_V4"
}
]
}
GHSA-XRGP-J4FJ-FQWR
Vulnerability from github – Published: 2024-03-05 12:30 – Updated: 2025-04-23 18:30A CWE-613 “Insufficient Session Expiration” vulnerability in the web application, due to the session cookie “sessionid” lasting two weeks, facilitates session hijacking attacks against victims. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.
{
"affected": [],
"aliases": [
"CVE-2023-45600"
],
"database_specific": {
"cwe_ids": [
"CWE-613"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-05T12:15:47Z",
"severity": "MODERATE"
},
"details": "A CWE-613 \u201cInsufficient Session Expiration\u201d vulnerability in the web application, due to the session cookie \u201csessionid\u201d lasting two weeks, facilitates session hijacking attacks against victims. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.",
"id": "GHSA-xrgp-j4fj-fqwr",
"modified": "2025-04-23T18:30:52Z",
"published": "2024-03-05T12:30:33Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45600"
},
{
"type": "WEB",
"url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2023-45600"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
"type": "CVSS_V3"
}
]
}
GHSA-XV59-GC3R-RF92
Vulnerability from github – Published: 2022-07-06 00:00 – Updated: 2022-07-15 20:44Old session tokens can be used to authenticate to the application and send authenticated requests.
{
"affected": [
{
"package": {
"ecosystem": "Go",
"name": "github.com/heroiclabs/nakama"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "3.12.0"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2022-2306"
],
"database_specific": {
"cwe_ids": [
"CWE-613"
],
"github_reviewed": true,
"github_reviewed_at": "2022-07-06T19:58:37Z",
"nvd_published_at": "2022-07-05T09:15:00Z",
"severity": "HIGH"
},
"details": "Old session tokens can be used to authenticate to the application and send authenticated requests.",
"id": "GHSA-xv59-gc3r-rf92",
"modified": "2022-07-15T20:44:19Z",
"published": "2022-07-06T00:00:30Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-2306"
},
{
"type": "WEB",
"url": "https://github.com/heroiclabs/nakama/commit/ce8d3921e2acd44ef8b5e6edfe595b6df067b166"
},
{
"type": "PACKAGE",
"url": "https://github.com/heroiclabs/nakama/v3"
},
{
"type": "WEB",
"url": "https://huntr.dev/bounties/35acf263-6db4-4310-ab27-4c3c3a53f796"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"type": "CVSS_V3"
}
],
"summary": "Insufficient Session Expiration in Nakama"
}
Mitigation
Set sessions/credentials expiration date.
No CAPEC attack patterns related to this CWE.