Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
CVE's Videos

← Terug naar CVE-database

CVE-2016-9479

HIGH · 7.5 CVSS Gepubliceerd: CWE-255

Beschrijving

The "lost password" functionality in b2evolution before 6.7.9 allows remote attackers to reset arbitrary user passwords via a crafted request.

Vendors

B2evolution

Affected products

B2evolution

References