Vulnerability in the password recovery mechanism of...
High severity
Unreviewed
Published
Sep 4, 2023
to the GitHub Advisory Database
•
Updated Apr 4, 2024
Description
Published by the National Vulnerability Database
Sep 4, 2023
Published to the GitHub Advisory Database
Sep 4, 2023
Last updated
Apr 4, 2024
Vulnerability in the password recovery mechanism of Password Recovery plugin for Roundcube, in its 1.2 version, which could allow a remote attacker to change an existing user´s password by adding a 6-digit numeric token. An attacker could create an automatic script to test all possible values because the platform has no limit on the number of requests.
References