Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hm5m-9phw-v9hq

Опубликовано: 10 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

EIP Plus developed by Hundred Plus has a Weak Password Recovery Mechanism vulnerability, allowing unauthenticated remote attacker to predict or brute-force the 'forgot password' link, thereby successfully resetting any user's password.

EIP Plus developed by Hundred Plus has a Weak Password Recovery Mechanism vulnerability, allowing unauthenticated remote attacker to predict or brute-force the 'forgot password' link, thereby successfully resetting any user's password.

EPSS

Процентиль: 31%
0.00117
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-640

Связанные уязвимости

CVSS3: 9.8
nvd
3 месяца назад

EIP Plus developed by Hundred Plus has a Weak Password Recovery Mechanism vulnerability, allowing unauthenticated remote attacker to predict or brute-force the 'forgot password' link, thereby successfully resetting any user's password.

EPSS

Процентиль: 31%
0.00117
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-640