PT-2024-31865 · Unknown · Lines Police Cad

Sourajeet Majumder

·

Published

2024-09-26

·

Updated

2024-10-01

·

CVE-2024-45979

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Lines Police CAD version 1.0
Description A host header injection issue allows attackers to obtain the password reset token via user interaction with a crafted password reset link, enabling them to arbitrarily reset other users' passwords and compromise their accounts.
Recommendations For Lines Police CAD version 1.0, consider disabling the password reset functionality until a patch is available to prevent exploitation of the host header injection issue. Restrict access to the password reset link to minimize the risk of attackers obtaining the password reset token. Avoid using crafted password reset links to prevent user interaction that could lead to account compromise.

Exploit

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2024-45979

Affected Products

Lines Police Cad