CVE-2014-2269
medium · 6.4modules/Users/ForgotPassword.php in vTiger 6.0 before Security Patch 2 allows remote attackers to reset the password for arbitrary users via a request containing the username, password, and confirmPassword parameters.
6.4
CVSS
15.8%
EPSS (exploit prob.)
97th
EPSS percentile
2014-04-22
Published
AV:N/AC:L/Au:N/C:N/I:P/A:P
Weaknesses
CWE-20
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| vtiger | vtiger_crm | 6.0.0 |
Check a specific version with /api/v1/cve/match.
References
- http://vtiger-crm.2324883.n4.nabble.com/Vtigercrm-developers-IMP-forgot-password-and-re-installation-security-fix-tt9786.html
- http://www.securityfocus.com/bid/66758
- http://vtiger-crm.2324883.n4.nabble.com/Vtigercrm-developers-IMP-forgot-password-and-re-installation-security-fix-tt9786.html
- http://www.securityfocus.com/bid/66758
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2014-2269