Описание
WWBN AVideo recovery notification bypass vulnerability
A recovery notification bypass vulnerability exists in the userRecoverPass.php captcha validation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to silently create a recovery pass code for any user.
Пакеты
Наименование
wwbn/avideo
composer
Затронутые версииВерсия исправления
<= 12.4
Отсутствует
Связанные уязвимости
CVSS3: 5.3
nvd
около 2 лет назад
A recovery notification bypass vulnerability exists in the userRecoverPass.php captcha validation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to the silent creation of a recovery pass code for any user.