Описание
The reset-password feature in MetInfo 6.0 allows remote attackers to change arbitrary passwords via vectors involving a Host HTTP header that is modified to specify a web server under the attacker's control.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:metinfo:metinfo:6.0.0:*:*:*:*:*:*:*
EPSS
Процентиль: 60%
0.00399
Низкий
8.8 High
CVSS3
4.3 Medium
CVSS2
Дефекты
NVD-CWE-noinfo
Связанные уязвимости
CVSS3: 8.8
github
больше 3 лет назад
The reset-password feature in MetInfo 6.0 allows remote attackers to change arbitrary passwords via vectors involving a Host HTTP header that is modified to specify a web server under the attacker's control.
EPSS
Процентиль: 60%
0.00399
Низкий
8.8 High
CVSS3
4.3 Medium
CVSS2
Дефекты
NVD-CWE-noinfo