macrozheng mall-tiny 1.0.1 is vulnerable to Incorrect...
High severity
Unreviewed
Published
Feb 1, 2025
to the GitHub Advisory Database
•
Updated Feb 3, 2025
Description
Published by the National Vulnerability Database
Jan 31, 2025
Published to the GitHub Advisory Database
Feb 1, 2025
Last updated
Feb 3, 2025
macrozheng mall-tiny 1.0.1 is vulnerable to Incorrect Access Control via the logout function. After a user logs out, their token is still available and fetches information in the logged-in state.
References