CVE-2017-8827

CRITICAL9.1EPSS 0.46%

GeniXCMS Arbitrary User Password Reset Vulnerability

發布日:2022/5/17修改日:2024/4/25

描述

forgotpassword.php in GeniXCMS lacks a rate limit, which might allow remote attackers to cause a denial of service (login inability) or possibly conduct Arbitrary User Password Reset attacks via a series of requests.

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1CRITICAL9.1CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

參考連結(4)