Описание
Taguette is an open source qualitative research tool. An issue has been discovered in Taguette versions prior to 1.5.0. It was possible for an attacker to request password reset email containing a malicious link, allowing the attacker to set the email if clicked by the victim. This issue has been patched in version 1.5.0.
Ссылки
- Issue TrackingVendor Advisory
- Issue TrackingVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.5.0 (включая)
cpe:2.3:a:taguette:taguette:*:*:*:*:*:*:*:*
EPSS
Процентиль: 10%
0.00036
Низкий
7.1 High
CVSS3
Дефекты
CWE-15
Связанные уязвимости
EPSS
Процентиль: 10%
0.00036
Низкий
7.1 High
CVSS3
Дефекты
CWE-15