Weak Password Recovery Mechanism for Forgotten Password in GitHub repository microweber/microweber prior to 1.3.
The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.
Link | Tags |
---|---|
https://huntr.dev/bounties/b36be8cd-544f-42bd-990d-aa1a46df44d7 | third party advisory exploit |
https://github.com/microweber/microweber/commit/a3944cf9d1d8c41a48297ddc98302934e2511b0f | third party advisory patch |