VulnerabilityModified
CVE-2019-15749
SITOS six Build v6.2.1 allows a user to change their password and recovery email address without requiring them to confirm the change with their old password.
MEDIUM 6.5EPSS 0.98%
Does this matter?
Lower severity and a low EPSS score (0.98%). Track it; it rarely justifies an emergency change on its own.
Description
SITOS six Build v6.2.1 allows a user to change their password and recovery email address without requiring them to confirm the change with their old password. This would allow an attacker with access to the victim's account (e.g., via XSS or an unattended workstation) to change that password and address.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
- EPSS
- 0.98% probability · 60th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-640
- Affected
- sitos/sitos six
- Source
- cve@mitre.org
References
- https://www.contextis.com/en/resources/advisories/cve-2019-15749Third Party Advisory
- https://www.contextis.com/en/resources/advisories/cve-2019-15749Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.