Unverified Password Change in GitHub repository phpfusion/phpfusion prior to 9.10.20.
When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
https://huntr.dev/bounties/b3f888d2-5c71-4682-8287-42613401fd5a | patch exploit third party advisory issue tracking |
https://github.com/phpfusion/phpfusion/commit/57c96d4a0c00e8e1e25100087654688123c6e991 | third party advisory patch |