PT-2015-3150 · Dovestones · Dovestones Ad Self Password Reset

Adam Caudill

·

Published

2015-12-24

·

Updated

2016-11-28

·

CVE-2015-8267

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Dovestones AD Self Password Reset versions prior to 3.0.4.0
Description The issue is related to the PasswordReset.Controllers.ResetController.ChangePasswordIndex method in PasswordReset.dll, which has inadequate access control. This allows remote attackers to reset arbitrary passwords via a crafted request with a valid username.
Recommendations For versions prior to 3.0.4.0, update to version 3.0.4.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the PasswordReset.Controllers.ResetController.ChangePasswordIndex method until a patch is available. Avoid using the username variable in the affected API endpoint until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-00365
CVE-2015-8267

Affected Products

Dovestones Ad Self Password Reset