Unrated severityNVD Advisory· Published Sep 17, 2020· Updated Aug 4, 2024
CVE-2020-25728
CVE-2020-25728
Description
The Reset Password add-on before 1.2.0 for Alfresco has a broken algorithm (involving an increment) that allows a malicious user to change any user's account password include the admin account.
Affected products
2- Alfresco/Reset Password add-ondescription
- Range: <1.2.0
Patches
Vulnerability mechanics
References
1- amriunix.com/post/alfresco-reset-password-add-on-0-day-vulnerabilities/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.