{ "id": "CVE-2024-29401", "sourceIdentifier": "cve@mitre.org", "published": "2024-03-26T15:15:49.620", "lastModified": "2024-03-26T17:09:53.043", "vulnStatus": "Awaiting Analysis", "descriptions": [ { "lang": "en", "value": "xzs-mysql 3.8 is vulnerable to Insufficient Session Expiration, which allows attackers to use the session of a deleted admin to do anything." }, { "lang": "es", "value": "xzs-mysql 3.8 es vulnerable a una caducidad de sesi\u00f3n insuficiente, lo que permite a los atacantes utilizar la sesi\u00f3n de un administrador eliminado para hacer cualquier cosa." } ], "metrics": {}, "references": [ { "url": "https://github.com/menghaining/PoC/blob/main/xzs-mysql/xzs-mysql%20--%20PoC.md", "source": "cve@mitre.org" } ] }