Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-459r-h7r8-fv25

Опубликовано: 14 дек. 2021
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

An issue was discovered in Reprise RLM 14.2. Because /goform/change_password_process does not verify authentication or authorization, an unauthenticated user can change the password of any existing user. This allows an attacker to change the password of any known user, thereby preventing valid users from accessing the system and granting the attacker full access to that user's account.

An issue was discovered in Reprise RLM 14.2. Because /goform/change_password_process does not verify authentication or authorization, an unauthenticated user can change the password of any existing user. This allows an attacker to change the password of any known user, thereby preventing valid users from accessing the system and granting the attacker full access to that user's account.

EPSS

Процентиль: 99%
0.86671
Высокий

9.8 Critical

CVSS3

Дефекты

CWE-287
CWE-306

Связанные уязвимости

CVSS3: 9.8
nvd
около 4 лет назад

An issue was discovered in Reprise RLM 14.2. Because /goform/change_password_process does not verify authentication or authorization, an unauthenticated user can change the password of any existing user. This allows an attacker to change the password of any known user, thereby preventing valid users from accessing the system and granting the attacker full access to that user's account.

EPSS

Процентиль: 99%
0.86671
Высокий

9.8 Critical

CVSS3

Дефекты

CWE-287
CWE-306