Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5rj4-v588-g378

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

membership.asp in Mini-Nuke CMS System 1.8.2 and earlier does not verify the old password when changing a password, which allows remote attackers to change the passwords of other members via a lostpassnew action with a modified x parameter.

membership.asp in Mini-Nuke CMS System 1.8.2 and earlier does not verify the old password when changing a password, which allows remote attackers to change the passwords of other members via a lostpassnew action with a modified x parameter.

EPSS

Процентиль: 80%
0.01425
Низкий

Дефекты

CWE-20

Связанные уязвимости

nvd
около 20 лет назад

membership.asp in Mini-Nuke CMS System 1.8.2 and earlier does not verify the old password when changing a password, which allows remote attackers to change the passwords of other members via a lostpassnew action with a modified x parameter.

EPSS

Процентиль: 80%
0.01425
Низкий

Дефекты

CWE-20