CVE-2016-9479
7.5HIGHThe "lost password" functionality in b2evolution before 6.7.9 allows remote attackers to reset arbitrary user passwords via a crafted request.
Publicado: 12/2/2016Actualizado: 4/12/2025
Descripción
The "lost password" functionality in b2evolution before 6.7.9 allows remote attackers to reset arbitrary user passwords via a crafted request.
Análisis IAImpulsado por IA
Productos Afectados
b2evolutionb2evolution
Referencias
- http://b2evolution.net/downloads/6-7-9-stablePatchRelease NotesVendor Advisory
- http://www.securityfocus.com/bid/95006Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1037393
- https://github.com/b2evolution/b2evolution/issues/33Issue TrackingPatchThird Party Advisory
- http://b2evolution.net/downloads/6-7-9-stablePatchRelease NotesVendor Advisory
- http://www.securityfocus.com/bid/95006Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1037393
- https://github.com/b2evolution/b2evolution/issues/33Issue TrackingPatchThird Party Advisory