PT-2023-10236 · Little Apps · Little Apps Little Software Stats

CVE-2015-10057

·

Publicado

2023-01-16

·

Atualizado

2024-05-17

CVSS v2.0

4.0

Média

VetorAV:A/AC:H/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Little Apps Little Software Stats versions prior to 0.2
Description A critical issue was found in the Password Reset Handler component, specifically in the file inc/class.securelogin.php, leading to improper access controls. The complexity of an attack is rather high, and exploitation appears to be difficult.
Recommendations For versions prior to 0.2, upgrade to version 0.2 to address this issue. As a temporary workaround, consider restricting access to the Password Reset Handler component until the upgrade is applied.

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-10057

Produtos afetados

Little Apps Little Software Stats