ZeroHour

CVE-2019-15749

CVSS 3.1
6.5 medium
EPSS
<1%p60
Published
()
Modified
Description

SITOS six Build v6.2.1 allows a user to change their password and recovery email address without requiring them to confirm the change with their old password. This would allow an attacker with access to the victim's account (e.g., via XSS or an unattended workstation) to change that password and address.

Vendors
sitos
Products
sitos six
Weakness
CWE-640
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.