Filtered by vendor Alfresco
Subscriptions
Filtered by product Reset Password
Subscriptions
Total
2 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2020-25728 | 1 Alfresco | 1 Reset Password | 2024-11-21 | 8.8 High |
The Reset Password add-on before 1.2.0 for Alfresco has a broken algorithm (involving an increment) that allows a malicious user to change any user's account password include the admin account. | ||||
CVE-2020-15181 | 1 Alfresco | 1 Reset Password | 2024-11-21 | 9.3 Critical |
The Alfresco Reset Password add-on before version 1.2.0 relies on untrusted inputs in a security decision. Intruders can get admin's access to the system using the vulnerability in the project. Impacts all servers where this add-on is installed. The problem is fixed in version 1.2.0 |
Page 1 of 1.