Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-44839

Опубликовано: 18 янв. 2022
Источник: nvd
CVSS3: 6.5
CVSS2: 4
EPSS Низкий

Описание

An issue was discovered in Delta RM 1.2. It is possible to request a new password for any other account using the account ID. Using the /listes/DTsendmaildata/adm_utilisateur/send-mail.json endpoint, a user can send a JSON array with user IDs that will have their passwords reset (and new ones sent to their respective e-mail addresses).

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:deltarm:delta_rm:1.2:*:*:*:*:*:*:*

EPSS

Процентиль: 36%
0.00152
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-640

Связанные уязвимости

github
около 4 лет назад

An issue was discovered in Delta RM 1.2. It is possible to request a new password for any other account using the account ID. Using the /listes/DTsendmaildata/adm_utilisateur/send-mail.json endpoint, a user can send a JSON array with user IDs that will have their passwords reset (and new ones sent to their respective e-mail addresses).

EPSS

Процентиль: 36%
0.00152
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-640