SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-15749

SITOS six Build v6.2.1 allows a user to change their password and recovery email address without requiring them to confirm the change with their old password.

MEDIUM 6.5EPSS 0.98%

Does this matter?

Lower severity and a low EPSS score (0.98%). Track it; it rarely justifies an emergency change on its own.

Description

SITOS six Build v6.2.1 allows a user to change their password and recovery email address without requiring them to confirm the change with their old password. This would allow an attacker with access to the victim's account (e.g., via XSS or an unattended workstation) to change that password and address.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
EPSS
0.98% probability · 60th percentile
CISA KEV
Not listed
Weakness
CWE-640
Affected
sitos/sitos six
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.