Логотип exploitDog
bind:CVE-2020-14930
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-14930

Количество 2

Количество 2

nvd логотип

CVE-2020-14930

больше 5 лет назад

An issue was discovered in BT CTROMS Terminal OS Port Portal CT-464. Account takeover can occur because the password-reset feature discloses the verification token. Upon a getverificationcode.jsp request, this token is transmitted not only to the registered phone number of the user account, but is also transmitted to the unauthenticated HTTP client.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-pvp3-4g5m-35pm

больше 3 лет назад

An issue was discovered in BT CTROMS Terminal OS Port Portal CT-464. Account takeover can occur because the password-reset feature discloses the verification token. Upon a getverificationcode.jsp request, this token is transmitted not only to the registered phone number of the user account, but is also transmitted to the unauthenticated HTTP client.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-14930

An issue was discovered in BT CTROMS Terminal OS Port Portal CT-464. Account takeover can occur because the password-reset feature discloses the verification token. Upon a getverificationcode.jsp request, this token is transmitted not only to the registered phone number of the user account, but is also transmitted to the unauthenticated HTTP client.

CVSS3: 8.1
6%
Низкий
больше 5 лет назад
github логотип
GHSA-pvp3-4g5m-35pm

An issue was discovered in BT CTROMS Terminal OS Port Portal CT-464. Account takeover can occur because the password-reset feature discloses the verification token. Upon a getverificationcode.jsp request, this token is transmitted not only to the registered phone number of the user account, but is also transmitted to the unauthenticated HTTP client.

6%
Низкий
больше 3 лет назад

Уязвимостей на страницу