CVE-2016-9479

7.5HIGH

The "lost password" functionality in b2evolution before 6.7.9 allows remote attackers to reset arbitrary user passwords via a crafted request.

发布于: 12/2/2016更新于: 4/12/2025

描述

The "lost password" functionality in b2evolution before 6.7.9 allows remote attackers to reset arbitrary user passwords via a crafted request.

AI分析AI驱动

受影响产品

b2evolutionb2evolution

参考资料