VYPR

Reset Password

by Alfresco

CVEs (2)

  • CVE-2020-25728HigSep 17, 2020
    risk 0.57cvss 8.8epss 0.01

    The Reset Password add-on before 1.2.0 for Alfresco has a broken algorithm (involving an increment) that allows a malicious user to change any user's account password include the admin account.

  • CVE-2020-15181CriSep 18, 2020
    risk 0.00cvss 9.3epss 0.01

    The Alfresco Reset Password add-on before version 1.2.0 relies on untrusted inputs in a security decision. Intruders can get admin's access to the system using the vulnerability in the project. Impacts all servers where this add-on is installed. The problem is fixed in version…