Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jjjm-vgrm-72p6

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

resetpass.php in openInvoice 0.90 beta and earlier allows remote authenticated users to change the passwords of arbitrary users via a modified uid parameter. NOTE: this can be leveraged with a separate vulnerability in auth.php to modify passwords without authentication.

resetpass.php in openInvoice 0.90 beta and earlier allows remote authenticated users to change the passwords of arbitrary users via a modified uid parameter. NOTE: this can be leveraged with a separate vulnerability in auth.php to modify passwords without authentication.

EPSS

Процентиль: 86%
0.0283
Низкий

Связанные уязвимости

nvd
почти 17 лет назад

resetpass.php in openInvoice 0.90 beta and earlier allows remote authenticated users to change the passwords of arbitrary users via a modified uid parameter. NOTE: this can be leveraged with a separate vulnerability in auth.php to modify passwords without authentication.

EPSS

Процентиль: 86%
0.0283
Низкий