The forgot password token basically just makes us capable of taking over the account of whoever comment in an app that we can see (bruteforcing comment id's might also be an option but I wouldn't count on it, since it would take a long time to find a valid one).
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-42454 | The forgot password token basically just makes us capable of taking over the account of whoever comment in an app that we can see (bruteforcing comment id's might also be an option but I wouldn't count on it, since it would take a long time to find a valid one). |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: @huntrdev
Published:
Updated: 2024-08-03T00:53:00.227Z
Reserved: 2022-08-29T00:00:00
Link: CVE-2022-3019
No data.
Status : Modified
Published: 2022-08-29T06:15:09.923
Modified: 2024-11-21T07:18:39.000
Link: CVE-2022-3019
No data.
OpenCVE Enrichment
No data.
EUVD