Client: Firefox or IE6+, Windows. (Tested FF 3.54 and 3.612)
Host: Sitellite 5.0.3 on Linux.
Firefox settings are largely default, except that password-caching
is disabled to ensure that isn't the issue. Issue does not seem to
affect other browsers.
Issue is that if I logon as an Editor or higher-level user, I
find that after closing and re-opening the browser, I can navigate
back in the browser's history to the previous Sitellite session,
and make further changes Without a password *
being required.
This applies EVEN if 'Remember User' is unchecked. Once this
situation is in-effect and you then log off, the 'Remember User'
tickbox disappears from from the logon-sidebar altogether.
I have altered the templates somewhat on the test site, but I
don't see how that could have any bearing on the issue.
It would seem that the exploit is time-limited to about 2h on a
computer in-use, but that the exploit may be feasible after a much
longer interval if the computer is shut-down after the
editing-session and left so until the intrusion-attempt. Still to
test this aspect fully, but it also seems quite possible that
(given a few minutes unobserved at the keyboard) the exploit could
be transferred to another computer, where the hacker could then
deface the site at leisure, with no time limit and no password ever
required.
As this forum is public, no tech details. Just try and see, it's
not difficult to replicate.
Mitigation:
ALWAYS log-off before closing the browser.
Set your browser to store cookies for the current session only.
Always close the browser.
HTH & Regards.