High severity7.5NVD Advisory· Published Dec 2, 2016· Updated May 6, 2026
CVE-2016-9479
CVE-2016-9479
Description
The "lost password" functionality in b2evolution before 6.7.9 allows remote attackers to reset arbitrary user passwords via a crafted request.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- b2evolution.net/downloads/6-7-9-stablenvdPatchRelease NotesVendor Advisory
- github.com/b2evolution/b2evolution/issues/33nvdIssue TrackingPatchThird Party Advisory
- www.securityfocus.com/bid/95006nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1037393nvd
News mentions
0No linked articles in our index yet.