Contao before 3.5.39 and 4.x before 4.7.3 has a Weak Password Recovery Mechanism for a Forgotten Password.
The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.
Link | Tags |
---|---|
https://contao.org/en/news.html | vendor advisory |
https://contao.org/en/news/security-vulnerability-cve-2019-10641.html | vendor advisory |