Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f3g3-8g37-3mvg

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

RunCMS before 1.6.1 does not require entry of the old password during a password change, which allows context-dependent attackers to change passwords upon obtaining temporary access to a session.

RunCMS before 1.6.1 does not require entry of the old password during a password change, which allows context-dependent attackers to change passwords upon obtaining temporary access to a session.

EPSS

Процентиль: 90%
0.06008
Низкий

Связанные уязвимости

nvd
около 18 лет назад

RunCMS before 1.6.1 does not require entry of the old password during a password change, which allows context-dependent attackers to change passwords upon obtaining temporary access to a session.

EPSS

Процентиль: 90%
0.06008
Низкий