PT-2014-3348 · E107 · E107
Published
2014-01-22
·
Updated
2014-01-23
·
CVE-2013-7305
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
e107 versions through 1.0.4
Description
The issue concerns the lack of validation for the user ban field in the fpw.php file. This oversight allows remote attackers to reset passwords by sending a 'pwsubmit' request, provided they have access to the e-mail account of a banned user.
Recommendations
For versions through 1.0.4, consider modifying the fpw.php file to include checks for the user ban field to prevent unauthorized password resets. As a temporary workaround, restrict access to the password reset functionality for banned users until a proper fix is implemented.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
E107