Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 4 min 109 bronnen 3 kritiek 28 vandaag
CVE's Videos

← Terug naar CVE-database

CVE-2014-9039

MEDIUM · 4.3 CVSS Gepubliceerd: CWE-254

Beschrijving

wp-login.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to reset passwords by leveraging access to an e-mail account that received a password-reset message.

Vendors

Debian Mageia Project Wordpress

Affected products

Debian Linux Mageia Wordpress

References