When a front end member changes their password, the corresponding remember-me tokens are not removed.
Update to Contao 4.13.40.
Disable "Allow auto login" in the login module.
https://contao.org/en/security-advisories/remember-me-tokens-are-not-cleared-after-a-password-change
If you have any questions or comments about this advisory, open an issue in contao/contao.
{
"github_reviewed_at": "2024-04-09T16:15:06Z",
"cwe_ids": [
"CWE-384",
"CWE-613"
],
"severity": "MODERATE",
"github_reviewed": true,
"nvd_published_at": "2024-04-09T17:16:02Z"
}