Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cp43-cj42-p4c3

Опубликовано: 29 сент. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

An authorization bypass in b2evolution allows remote, unauthenticated attackers to predict password reset tokens for any user through the use of a bad randomness function. This allows the attacker to get valid sessions for arbitrary users, and optionally reset their password. Tested and confirmed in a default installation of version 7.2.3. Earlier versions are affected, possibly earlier major versions as well.

An authorization bypass in b2evolution allows remote, unauthenticated attackers to predict password reset tokens for any user through the use of a bad randomness function. This allows the attacker to get valid sessions for arbitrary users, and optionally reset their password. Tested and confirmed in a default installation of version 7.2.3. Earlier versions are affected, possibly earlier major versions as well.

EPSS

Процентиль: 81%
0.01507
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-330

Связанные уязвимости

CVSS3: 9.1
nvd
больше 3 лет назад

An authorization bypass in b2evolution allows remote, unauthenticated attackers to predict password reset tokens for any user through the use of a bad randomness function. This allows the attacker to get valid sessions for arbitrary users, and optionally reset their password. Tested and confirmed in a default installation of version 7.2.3. Earlier versions are affected, possibly earlier major versions as well.

EPSS

Процентиль: 81%
0.01507
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-330