PT-2019-11286 · Dedecms · Dedecms
Published
2019-03-24
·
Updated
2020-08-24
·
CVE-2019-10014
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
DedeCMS version 5.7SP2
Description:
The issue allows remote authenticated users to reset the passwords of arbitrary users. This is possible due to improper validation of the
key parameter in the member/resetpassword.php script, which can be exploited by modifying the id parameter.Recommendations:
For DedeCMS version 5.7SP2, as a temporary workaround, consider restricting access to the
member/resetpassword.php script until a proper fix is available, or ensure that the key parameter is properly validated to prevent unauthorized password resets.Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dedecms