CVEs Blog | G5 Cyber Security

CVE-2020-25728 – The Reset Password add-on before 1.2.0 for Alfresco has a broken algorith

The Reset Password add-on before 1.2.0 for Alfresco has a broken algorithm (involving an increment) that allows a malicious user to change any user’s account password include the admin account.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25728

Reference (s):

Exit mobile version