PT-2024-31865 · Unknown · Lines Police Cad
Sourajeet Majumder
·
Published
2024-09-26
·
Updated
2024-10-01
·
CVE-2024-45979
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Lines Police CAD version 1.0
Description
A host header injection issue allows attackers to obtain the password reset token via user interaction with a crafted password reset link, enabling them to arbitrarily reset other users' passwords and compromise their accounts.
Recommendations
For Lines Police CAD version 1.0, consider disabling the password reset functionality until a patch is available to prevent exploitation of the host header injection issue. Restrict access to the password reset link to minimize the risk of attackers obtaining the password reset token. Avoid using crafted password reset links to prevent user interaction that could lead to account compromise.
Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lines Police Cad