Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-875w-x894-8p6c

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The password reset functionality in Simple Machines Forum (SMF) 1.0.x before 1.0.14, 1.1.x before 1.1.6, and 2.0 before 2.0 beta 4 includes clues about the random number generator state within a hidden form field and generates predictable validation codes, which allows remote attackers to modify passwords of other users and gain privileges.

The password reset functionality in Simple Machines Forum (SMF) 1.0.x before 1.0.14, 1.1.x before 1.1.6, and 2.0 before 2.0 beta 4 includes clues about the random number generator state within a hidden form field and generates predictable validation codes, which allows remote attackers to modify passwords of other users and gain privileges.

EPSS

Процентиль: 90%
0.05711
Низкий

Связанные уязвимости

nvd
больше 16 лет назад

The password reset functionality in Simple Machines Forum (SMF) 1.0.x before 1.0.14, 1.1.x before 1.1.6, and 2.0 before 2.0 beta 4 includes clues about the random number generator state within a hidden form field and generates predictable validation codes, which allows remote attackers to modify passwords of other users and gain privileges.

EPSS

Процентиль: 90%
0.05711
Низкий