PT-2023-10236 · Little Apps · Little Apps Little Software Stats

Published

2023-01-16

·

Updated

2024-05-17

·

CVE-2015-10057

CVSS v2.0

4.0

Medium

VectorAV:A/AC:H/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Little Apps Little Software Stats versions prior to 0.2
Description A critical issue was found in the Password Reset Handler component, specifically in the file inc/class.securelogin.php, leading to improper access controls. The complexity of an attack is rather high, and exploitation appears to be difficult.
Recommendations For versions prior to 0.2, upgrade to version 0.2 to address this issue. As a temporary workaround, consider restricting access to the Password Reset Handler component until the upgrade is applied.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2015-10057

Affected Products

Little Apps Little Software Stats