MEDIUM
classes/admin.class.php in CubeCart 5.2.12 through 5.2.16 and 6.x before 6.0.7 does not properly validate that a password reset request was made, which allows remote attackers to change the administrator password via a recovery request with a space character in the validate parameter and the administrator email in the email parameter
Published Sep 28, 2015
6.8
MEDIUMCVSS 2.0
EPSS 2.19%
Description
Affected products
Remediation
Metrics
References (4)
Change history (0)
No recorded changes yet.