VulnerabilityModified
CVE-2023-4381
Unverified Password Change in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
MEDIUM 4.3EPSS 0.43%
Does this matter?
Lower severity and a low EPSS score (0.43%). Track it; it rarely justifies an emergency change on its own.
Description
Unverified Password Change in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.43% probability · 37th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-620
- Affected
- instantcms/instantcms
- Source
- security@huntr.dev
References
- https://github.com/instantsoft/icms2/commit/58f8b9941b53b606a1b15a4364005cd2b1965507Patch
- https://huntr.dev/bounties/666c2617-e3e9-4955-9c97-2f8ed5262cc3Patch, Third Party Advisory
- https://github.com/instantsoft/icms2/commit/58f8b9941b53b606a1b15a4364005cd2b1965507Patch
- https://huntr.dev/bounties/666c2617-e3e9-4955-9c97-2f8ed5262cc3Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.