Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rp89-32rp-qpq2

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Pagekit Weak Password Recovery Mechanism for Forgotten Password

An issue was discovered in Pagekit CMS before 1.0.11. In this vulnerability the remote attacker is able to reset the registered user's password, when the debug toolbar is enabled. The password is successfully recovered using this exploit. The SecureLayer7 ID is SL7_PGKT_01.

Пакеты

Наименование

pagekit/pagekit

composer
Затронутые версииВерсия исправления

< 1.0.11

1.0.11

EPSS

Процентиль: 89%
0.04961
Низкий

7.5 High

CVSS3

Дефекты

CWE-640

Связанные уязвимости

CVSS3: 7.5
nvd
около 9 лет назад

An issue was discovered in Pagekit CMS before 1.0.11. In this vulnerability the remote attacker is able to reset the registered user's password, when the debug toolbar is enabled. The password is successfully recovered using this exploit. The SecureLayer7 ID is SL7_PGKT_01.

EPSS

Процентиль: 89%
0.04961
Низкий

7.5 High

CVSS3

Дефекты

CWE-640