Описание
An issue was discovered in Concrete CMS before 8.5.7. The Dashboard allows a user's password to be changed without a prompt for the current password.
Ссылки
- Release NotesVendor Advisory
- Permissions Required
- Release NotesVendor Advisory
- Permissions Required
Уязвимые конфигурации
Конфигурация 1Версия до 8.5.7 (исключая)
cpe:2.3:a:concretecms:concrete_cms:*:*:*:*:*:*:*:*
EPSS
Процентиль: 92%
0.09143
Низкий
7.2 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-732
Связанные уязвимости
github
около 4 лет назад
An issue was discovered in Concrete CMS before 8.5.7. The Dashboard allows a user's password to be changed without a prompt for the current password.
EPSS
Процентиль: 92%
0.09143
Низкий
7.2 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-732