Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9qfg-3vc9-gp3w

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In InfiniteWP Admin Panel before 3.1.12.3, resetPasswordSendMail generates a weak password-reset code, which makes it easier for remote attackers to conduct admin Account Takeover attacks.

In InfiniteWP Admin Panel before 3.1.12.3, resetPasswordSendMail generates a weak password-reset code, which makes it easier for remote attackers to conduct admin Account Takeover attacks.

EPSS

Процентиль: 72%
0.00703
Низкий

Дефекты

CWE-338

Связанные уязвимости

CVSS3: 9.8
nvd
около 5 лет назад

In InfiniteWP Admin Panel before 3.1.12.3, resetPasswordSendMail generates a weak password-reset code, which makes it easier for remote attackers to conduct admin Account Takeover attacks.

EPSS

Процентиль: 72%
0.00703
Низкий

Дефекты

CWE-338