reset-password.php in ProjectSend before r1295 allows remote attackers to reset a password because of incorrect business logic. Errors are not properly considered (an invalid token parameter).
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
https://github.com/projectsend/projectsend/commits/master | third party advisory patch |
http://projectsend.com | vendor advisory |
https://github.com/varandinawer/CVE-2020-28874 | third party advisory exploit |
https://github.com/projectsend/projectsend/commit/440204734e9a1687cb9887e1c887173d23c5a93e | third party advisory patch |
https://github.com/projectsend/projectsend/releases/tag/r1295 | third party advisory release notes |