An insufficient entropy vulnerability exists in the userRecoverPass.php recoverPass generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to an arbitrary user password recovery. An attacker can send an HTTP request to trigger this vulnerability.
CVSS
No CVSS.
References
Configurations
No configuration.
Information
Published : 2024-01-10 16:15
Updated : 2024-01-10 18:15
NVD link : CVE-2023-49589
Mitre link : CVE-2023-49589
JSON object : View
Products Affected
No product.
CWE
No CWE.
