Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mxmv-qp6q-4xjp

Опубликовано: 01 дек. 2021
Источник: github
Github: Не прошло ревью

Описание

An issue was discovered in Concrete CMS before 8.5.7. The Dashboard allows a user's password to be changed without a prompt for the current password.

An issue was discovered in Concrete CMS before 8.5.7. The Dashboard allows a user's password to be changed without a prompt for the current password.

EPSS

Процентиль: 92%
0.09143
Низкий

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 7.2
nvd
около 4 лет назад

An issue was discovered in Concrete CMS before 8.5.7. The Dashboard allows a user's password to be changed without a prompt for the current password.

EPSS

Процентиль: 92%
0.09143
Низкий

Дефекты

CWE-732