VulnerabilityModified
CVE-2014-2269
modules/Users/ForgotPassword.php in vTiger 6.0 before Security Patch 2 allows remote attackers to reset the password for arbitrary users via a request containing the username, password, and confirmPassword parameters.
MEDIUM 6.4EPSS 15.8%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 15.8%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
modules/Users/ForgotPassword.php in vTiger 6.0 before Security Patch 2 allows remote attackers to reset the password for arbitrary users via a request containing the username, password, and confirmPassword parameters.
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
- EPSS
- 15.78% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- vtiger/vtiger crm
- Source
- cve@mitre.org
References
- http://vtiger-crm.2324883.n4.nabble.com/Vtigercrm-developers-IMP-forgot-password-and-re-installation-security-fix-tt9786.htmlPatch
- http://www.securityfocus.com/bid/66758Exploit
- http://vtiger-crm.2324883.n4.nabble.com/Vtigercrm-developers-IMP-forgot-password-and-re-installation-security-fix-tt9786.htmlPatch
- http://www.securityfocus.com/bid/66758Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.