Описание
The "forgot password" function in OneOrZero Helpdesk before 1.6.5.4 generates insecure passwords by concatenating the current timestamp with the username, which allows remote attackers to gain access as an arbitrary user by requesting a password reset.
Ссылки
- Patch
- Vendor Advisory
- ExploitVendor Advisory
- Patch
- Vendor Advisory
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.6.5.3 (включая)
Одно из
cpe:2.3:a:oneorzero:oneorzero_helpdesk:*:*:*:*:*:*:*:*
cpe:2.3:a:oneorzero:oneorzero_helpdesk:1.6:*:*:*:*:*:*:*
cpe:2.3:a:oneorzero:oneorzero_helpdesk:1.6.3:*:*:*:*:*:*:*
cpe:2.3:a:oneorzero:oneorzero_helpdesk:1.6.4:*:*:*:*:*:*:*
EPSS
Процентиль: 77%
0.01853
Низкий
7.5 High
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
больше 4 лет назад
The "forgot password" function in OneOrZero Helpdesk before 1.6.5.4 generates insecure passwords by concatenating the current timestamp with the username, which allows remote attackers to gain access as an arbitrary user by requesting a password reset.
EPSS
Процентиль: 77%
0.01853
Низкий
7.5 High
CVSS2
Дефекты
NVD-CWE-Other