PT-2023-25589 · Ilias · Ilias
CVE-2023-36487
·
Publicado
2023-06-29
·
Atualizado
2024-11-26
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ILIAS versions 7.0 beta1 through 7.20
ILIAS versions 8.0 beta1 through 8.1
Description
The password reset function allows remote attackers to take over the account.
Recommendations
For ILIAS versions 7.0 beta1 through 7.20, consider disabling the password reset function until a patch is available.
For ILIAS versions 8.0 beta1 through 8.1, consider disabling the password reset function until a patch is available.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ilias