Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 8 min 105 bronnen 1 kritiek 32 vandaag
CVE's Videos

← Terug naar CVE-database

CVE-2015-6928

MEDIUM · 6.8 CVSS Gepubliceerd: CWE-284

Beschrijving

classes/admin.class.php in CubeCart 5.2.12 through 5.2.16 and 6.x before 6.0.7 does not properly validate that a password reset request was made, which allows remote attackers to change the administrator password via a recovery request with a space character in the validate parameter and the administrator email in the email parameter.

Vendors

Cubecart

Affected products

Cubecart

References