Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-6203

Опубликовано: 06 авг. 2024
Источник: nvd
CVSS3: 8.3
CVSS3: 8.1
EPSS Низкий

Описание

HaloITSM versions up to 2.146.1 are affected by a Password Reset Poisoning vulnerability. Poisoned password reset links can be sent to existing HaloITSM users (given their email address is known). When these poisoned links get accessed (e.g. manually by the victim or automatically by an email client software), the password reset token is leaked to the malicious actor, allowing them to set a new password for the victim's account.This potentially leads to account takeover attacks.HaloITSM versions past 2.146.1 (and patches starting from 2.143.61 ) fix the mentioned vulnerability.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:haloservicesolutions:haloitsm:*:*:*:*:*:*:*:*
Версия до 2.143.61 (исключая)
cpe:2.3:a:haloservicesolutions:haloitsm:*:*:*:*:*:*:*:*
Версия от 2.144 (включая) до 2.146.1 (исключая)

EPSS

Процентиль: 45%
0.00224
Низкий

8.3 High

CVSS3

8.1 High

CVSS3

Дефекты

CWE-640
CWE-640

Связанные уязвимости

CVSS3: 8.3
github
больше 1 года назад

HaloITSM versions up to 2.146.1 are affected by a Password Reset Poisoning vulnerability. Poisoned password reset links can be sent to existing HaloITSM users (given their email address is known). When these poisoned links get accessed (e.g. manually by the victim or automatically by an email client software), the password reset token is leaked to the malicious actor, allowing them to set a new password for the victim's account.This potentially leads to account takeover attacks.HaloITSM versions past 2.146.1 (and patches starting from 2.143.61 ) fix the mentioned vulnerability.

EPSS

Процентиль: 45%
0.00224
Низкий

8.3 High

CVSS3

8.1 High

CVSS3

Дефекты

CWE-640
CWE-640