PT-2019-11286 · Dedecms · Dedecms

Published

2019-03-24

·

Updated

2020-08-24

·

CVE-2019-10014

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: DedeCMS version 5.7SP2
Description: The issue allows remote authenticated users to reset the passwords of arbitrary users. This is possible due to improper validation of the key parameter in the member/resetpassword.php script, which can be exploited by modifying the id parameter.
Recommendations: For DedeCMS version 5.7SP2, as a temporary workaround, consider restricting access to the member/resetpassword.php script until a proper fix is available, or ensure that the key parameter is properly validated to prevent unauthorized password resets.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-10014

Affected Products

Dedecms