PT-2014-3348 · E107 · E107

Published

2014-01-22

·

Updated

2014-01-23

·

CVE-2013-7305

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions e107 versions through 1.0.4
Description The issue concerns the lack of validation for the user ban field in the fpw.php file. This oversight allows remote attackers to reset passwords by sending a 'pwsubmit' request, provided they have access to the e-mail account of a banned user.
Recommendations For versions through 1.0.4, consider modifying the fpw.php file to include checks for the user ban field to prevent unauthorized password resets. As a temporary workaround, restrict access to the password reset functionality for banned users until a proper fix is implemented.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-7305

Affected Products

E107