id: PYSEC-2021-341 details: Incorrect Access Control in Lin-CMS-Flask v0.1.1 allows remote attackers to obtain sensitive information and/or gain privileges due to the application not invalidating a user's authentication token upon logout, which allows for replaying packets. aliases: - CVE-2020-18701 modified: '2022-03-16T02:19:50.092963Z' published: '2021-08-16T18:15:00Z' references: - type: REPORT url: https://github.com/TaleLin/lin-cms-flask/issues/30 affected: - package: name: lin-cms ecosystem: PyPI purl: pkg:pypi/lin-cms ranges: - type: ECOSYSTEM events: - introduced: '0' versions: - 0.1.1a1 - 0.1.1a2 - 0.1.1a3 - 0.1.1a4 - 0.1.1a5 - 0.1.1a6 - 0.1.1a7 - 0.1.1a8 - 0.1.1b1 - 0.1.1b2 - 0.1.1b3 - 0.1.1b4 - 0.2.0b1 - 0.2.0b2 - 0.2.0b3 - 0.3.0a10 - 0.3.0a2 - 0.3.0a3 - 0.3.0a4 - 0.3.0a5 - 0.3.0a6 - 0.3.0a7 - 0.3.0a8 - 0.3.0a9 - 0.3.1 - 0.4.0 - 0.4.2 - 0.4.3 - 0.4.4 - 0.4.5 - 0.4.6 - 0.4.7 - 0.4.8