Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fq56-2x8j-2w4x

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Password reset tokens in Magento CE before 1.9.2.2, and Magento EE before 1.14.2.2 are passed via a GET request and not canceled after use, which allows remote attackers to obtain user passwords via a crafted external service with access to the referrer field.

Password reset tokens in Magento CE before 1.9.2.2, and Magento EE before 1.14.2.2 are passed via a GET request and not canceled after use, which allows remote attackers to obtain user passwords via a crafted external service with access to the referrer field.

EPSS

Процентиль: 42%
0.00203
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 9.8
nvd
больше 8 лет назад

Password reset tokens in Magento CE before 1.9.2.2, and Magento EE before 1.14.2.2 are passed via a GET request and not canceled after use, which allows remote attackers to obtain user passwords via a crafted external service with access to the referrer field.

EPSS

Процентиль: 42%
0.00203
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-200