Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5qq2-qmp3-f37q

Опубликовано: 15 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.4

Описание

Creativeitem Academy LMS up to and including 5.13 uses predictable password reset tokens based on Base64 encoded templates without rate limiting, allowing brute force attacks to guess valid reset tokens and compromise user accounts.

Creativeitem Academy LMS up to and including 5.13 uses predictable password reset tokens based on Base64 encoded templates without rate limiting, allowing brute force attacks to guess valid reset tokens and compromise user accounts.

EPSS

Процентиль: 23%
0.00075
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-640

Связанные уязвимости

CVSS3: 6.4
nvd
4 месяца назад

Creativeitem Academy LMS up to and including 5.13 uses predictable password reset tokens based on Base64 encoded templates without rate limiting, allowing brute force attacks to guess valid reset tokens and compromise user accounts.

EPSS

Процентиль: 23%
0.00075
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-640