Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w5wr-pv9p-hfhr

Опубликовано: 13 июн. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.4

Описание

Authentication Bypass by Spoofing vulnerability in the password reset process of Pandora FMS allows an unauthenticated attacker to initiate a password reset process for any user account without proper authentication. This issue affects PandoraFMS v771 and prior versions on all platforms.

Authentication Bypass by Spoofing vulnerability in the password reset process of Pandora FMS allows an unauthenticated attacker to initiate a password reset process for any user account without proper authentication. This issue affects PandoraFMS v771 and prior versions on all platforms.

EPSS

Процентиль: 20%
0.00063
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-290

Связанные уязвимости

CVSS3: 6.4
nvd
больше 2 лет назад

Authentication Bypass by Spoofing vulnerability in the password reset process of Pandora FMS allows an unauthenticated attacker to initiate a password reset process for any user account without proper authentication. This issue affects PandoraFMS v771 and prior versions on all platforms.

EPSS

Процентиль: 20%
0.00063
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-290