Click Studios · Clickstudios Passwordstate Password Reset Portal · CVE-2020-26061
**Name of the Vulnerable Software and Affected Versions**
ClickStudios Passwordstate Password Reset Portal versions prior to 8501
**Description**
The issue concerns an authentication bypass. Specifically, the `ResetPassword` function does not validate whether the user has successfully authenticated using security questions. This allows an unauthenticated, remote attacker to send a crafted HTTP request to the "/account/ResetPassword" page to set a new password for any registered user.
**Recommendations**
For versions prior to 8501, update to build 8501 or later to resolve the issue. As a temporary workaround, consider restricting access to the "/account/ResetPassword" page until the update is applied.