Логотип exploitDog
bind:CVE-2021-36804
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-36804

Количество 2

Количество 2

nvd логотип

CVE-2021-36804

больше 4 лет назад

Akaunting version 2.1.12 and earlier suffers from a password reset spoofing vulnerability, wherein an attacker can proxy password reset requests through a running Akaunting instance, if that attacker knows the target's e-mail address. This issue was fixed in version 2.1.13 of the product. Please note that this issue is ultimately caused by the defaults provided by the Laravel framework, specifically how proxy headers are handled with respect to multi-tenant implementations. In other words, while this is not technically a vulnerability in Laravel, this default configuration is very likely to lead to practically identical identical vulnerabilities in Laravel projects that implement multi-tenant applications.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-246r-r2wf-frhx

около 4 лет назад

Malicious password-reset in Akaunting

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-36804

Akaunting version 2.1.12 and earlier suffers from a password reset spoofing vulnerability, wherein an attacker can proxy password reset requests through a running Akaunting instance, if that attacker knows the target's e-mail address. This issue was fixed in version 2.1.13 of the product. Please note that this issue is ultimately caused by the defaults provided by the Laravel framework, specifically how proxy headers are handled with respect to multi-tenant implementations. In other words, while this is not technically a vulnerability in Laravel, this default configuration is very likely to lead to practically identical identical vulnerabilities in Laravel projects that implement multi-tenant applications.

CVSS3: 5.4
0%
Низкий
больше 4 лет назад
github логотип
GHSA-246r-r2wf-frhx

Malicious password-reset in Akaunting

CVSS3: 8.1
0%
Низкий
около 4 лет назад

Уязвимостей на страницу