Weak Password Recovery Mechanism for Forgotten Password
CVE-2022-23172
Summary
An attacker can access to "Forgot my password" button, as soon as he puts users is valid in the system, the system would issue a message that a password reset email had been sent to user. This way you can verify which users are in the system and which are not.
- LOW
- ADJACENT_NETWORK
- LOW
- UNCHANGED
- NONE
- LOW
- LOW
- LOW
CWE-640 - Weak Password Recovery Mechanism for Forgotten Password
The software contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.
References
Advisory Timeline
- Published