Web Application Vulnerability in Dotclear by Dotclear
CVE-2016-7903

3.7LOW

Key Information:

Vendor

Dotclear

Status
Vendor
CVE Published:
4 January 2017

What is CVE-2016-7903?

A vulnerability in Dotclear versions before 2.10.3 allows remote attackers to alter the password reset address link by exploiting the HTTP Host header when it is omitted from the web server routing process. This can lead to unauthorized access or manipulation of user accounts, thereby posing a significant security risk to users leveraging the affected versions of this popular content management system.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.