説明
The "lost password" functionality in b2evolution before 6.7.9 allows remote attackers to reset arbitrary user passwords via a crafted request.
AI分析AIによる分析
影響を受ける製品
b2evolutionb2evolution
参照
- http://b2evolution.net/downloads/6-7-9-stablePatchRelease NotesVendor Advisory
- http://www.securityfocus.com/bid/95006Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1037393
- https://github.com/b2evolution/b2evolution/issues/33Issue TrackingPatchThird Party Advisory
- http://b2evolution.net/downloads/6-7-9-stablePatchRelease NotesVendor Advisory
- http://www.securityfocus.com/bid/95006Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1037393
- https://github.com/b2evolution/b2evolution/issues/33Issue TrackingPatchThird Party Advisory