ZPanel 10.0.1 has insufficient entropy for its password reset process.
The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/56400 | vdb entry third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/79841 | vdb entry third party advisory |