Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9q8p-c2mj-7c5v

Опубликовано: 01 мая 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

OpenText BizManager before 16.6.0.1 does not perform proper validation during the change-password operation. This allows any authenticated user to change the password of any other user, including the Administrator account.

OpenText BizManager before 16.6.0.1 does not perform proper validation during the change-password operation. This allows any authenticated user to change the password of any other user, including the Administrator account.

EPSS

Процентиль: 30%
0.00112
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-287
CWE-295

Связанные уязвимости

CVSS3: 9.8
nvd
почти 3 года назад

OpenText BizManager before 16.6.0.1 does not perform proper validation during the change-password operation. This allows any authenticated user to change the password of any other user, including the Administrator account.

EPSS

Процентиль: 30%
0.00112
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-287
CWE-295