Incorrect access control in the Forgot Your Password function of EMSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a crafted password reset token.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://secpro.llc/emsigner-cve-2/ | third party advisory exploit |