Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-phf3-pr25-c9c3

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

SITOS six Build v6.2.1 allows a user to change their password and recovery email address without requiring them to confirm the change with their old password. This would allow an attacker with access to the victim's account (e.g., via XSS or an unattended workstation) to change that password and address.

SITOS six Build v6.2.1 allows a user to change their password and recovery email address without requiring them to confirm the change with their old password. This would allow an attacker with access to the victim's account (e.g., via XSS or an unattended workstation) to change that password and address.

EPSS

Процентиль: 43%
0.00209
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-640

Связанные уязвимости

CVSS3: 6.5
nvd
больше 6 лет назад

SITOS six Build v6.2.1 allows a user to change their password and recovery email address without requiring them to confirm the change with their old password. This would allow an attacker with access to the victim's account (e.g., via XSS or an unattended workstation) to change that password and address.

EPSS

Процентиль: 43%
0.00209
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-640