PT-2022-27339 · Seeddms · Seeddms

Admin

·

Published

2022-12-08

·

Updated

2022-12-12

·

CVE-2022-44938

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SeedDMS versions 5.1.7 through 6.0.20
Description The issue is related to weak reset token generation, allowing attackers to execute a full account takeover via a brute force attack.
Recommendations For SeedDMS version 5.1.7, update to a version that addresses the weak reset token generation issue. For SeedDMS version 6.0.20, update to a version that addresses the weak reset token generation issue. As a temporary workaround, consider restricting access to the account reset functionality until a patch is available.

Exploit

Fix

Use of Insufficiently Random Values

Weakness Enumeration

Related Identifiers

CVE-2022-44938

Affected Products

Seeddms