CVE-2023-49589

An insufficient entropy vulnerability exists in the userRecoverPass.php recoverPass generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to an arbitrary user password recovery. An attacker can send an HTTP request to trigger this vulnerability.
CVSS

No CVSS.

Configurations

No configuration.

Information

Published : 2024-01-10 16:15

Updated : 2024-01-10 18:15


NVD link : CVE-2023-49589

Mitre link : CVE-2023-49589


JSON object : View

Products Affected

No product.

CWE

No CWE.