Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pqjh-4hfv-gw8h

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords upon an unauthenticated request, and then sends e-mail with a predictable (date-based) password to the admin, which makes it easier for remote attackers to obtain access by predicting this new password. This is related to the use of gmdate for password creation in fn_connect.php.

gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords upon an unauthenticated request, and then sends e-mail with a predictable (date-based) password to the admin, which makes it easier for remote attackers to obtain access by predicting this new password. This is related to the use of gmdate for password creation in fn_connect.php.

EPSS

Процентиль: 97%
0.36893
Средний

9.8 Critical

CVSS3

Дефекты

CWE-640

Связанные уязвимости

CVSS3: 9.8
nvd
около 8 лет назад

gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords upon an unauthenticated request, and then sends e-mail with a predictable (date-based) password to the admin, which makes it easier for remote attackers to obtain access by predicting this new password. This is related to the use of gmdate for password creation in fn_connect.php.

EPSS

Процентиль: 97%
0.36893
Средний

9.8 Critical

CVSS3

Дефекты

CWE-640