Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g8rg-59wq-2wg9

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

classes/admin.class.php in CubeCart 5.2.12 through 5.2.16 and 6.x before 6.0.7 does not properly validate that a password reset request was made, which allows remote attackers to change the administrator password via a recovery request with a space character in the validate parameter and the administrator email in the email parameter.

classes/admin.class.php in CubeCart 5.2.12 through 5.2.16 and 6.x before 6.0.7 does not properly validate that a password reset request was made, which allows remote attackers to change the administrator password via a recovery request with a space character in the validate parameter and the administrator email in the email parameter.

EPSS

Процентиль: 70%
0.00624
Низкий

Дефекты

CWE-284

Связанные уязвимости

nvd
больше 10 лет назад

classes/admin.class.php in CubeCart 5.2.12 through 5.2.16 and 6.x before 6.0.7 does not properly validate that a password reset request was made, which allows remote attackers to change the administrator password via a recovery request with a space character in the validate parameter and the administrator email in the email parameter.

EPSS

Процентиль: 70%
0.00624
Низкий

Дефекты

CWE-284