gougucms v4.08.18 was discovered to contain a password reset poisoning vulnerability which allows attackers to arbitrarily reset users' passwords via a crafted packet.
The product does not clean up its state or incorrectly cleans up its state when an exception is thrown, leading to unexpected state or control flow.
Link | Tags |
---|---|
https://gitee.com/gouguopen/gougucms/issues/I88TKH | third party advisory issue tracking exploit |