Description
In “SuiteCRM” application, v7.1.7 through v7.10.31 and v7.11-beta through v7.11.20 fail to properly invalidate password reset links that is associated with a deleted user id, which makes it possible for account takeover of any newly created user with the same user id.
No analysis available yet.
Remediation
Vendor Solution
Update to v7.10.32 or v7.11.21
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-12802 | In “SuiteCRM” application, v7.1.7 through v7.10.31 and v7.11-beta through v7.11.20 fail to properly invalidate password reset links that is associated with a deleted user id, which makes it possible for account takeover of any newly created user with the same user id. |
References
History
No history.
Status: PUBLISHED
Assigner: Mend
Published:
Updated: 2024-09-17T02:07:00.169Z
Reserved: 2021-01-22T00:00:00.000Z
Link: CVE-2021-25961
No data.
Status : Modified
Published: 2021-09-29T14:15:08.010
Modified: 2024-11-21T05:55:40.920
Link: CVE-2021-25961
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD