classes/admin.class.php in CubeCart 5.2.12 through 5.2.16 and 6.x before 6.0.7 does not properly validate that a password reset request was made, which allows remote attackers to change the administrator password via a recovery request with a space character in the validate parameter and the administrator email in the email parameter.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2015-09-28T15:00:00
Updated: 2024-08-06T07:36:34.395Z
Reserved: 2015-09-14T00:00:00
Link: CVE-2015-6928
Vulnrichment
No data.
NVD
Status : Modified
Published: 2015-09-28T15:59:01.627
Modified: 2024-11-21T02:35:53.670
Link: CVE-2015-6928
Redhat
No data.