ZeroHour

CVE-2020-27408

PoC
CVSS 3.1
7.5 high
EPSS
2%p76
Published
()
Modified
Description

OpenSIS Community Edition through 7.6 is affected by incorrect access controls for the file ResetUserInfo.php that allow an unauthenticated attacker to change the password of arbitrary users.

Vendors
os4ed
Products
opensis
Weakness
CWE-287, CWE-640
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.