PT-2024-22373 · Web-Flash · Web-Flash

Published

2024-04-08

·

Updated

2024-08-01

·

CVE-2024-28270

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions web-flash version 3.0
Description An issue in web-flash allows attackers to reset passwords for arbitrary users via a crafted POST request to "/prod-api/user/resetPassword".
Recommendations For web-flash version 3.0, consider disabling the password reset functionality via the "/prod-api/user/resetPassword" endpoint until a patch is available. Restrict access to this endpoint to minimize the risk of exploitation. Avoid using the password reset feature in the affected version until the issue is resolved.

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-28270

Affected Products

Web-Flash