Remote Password Reset Vulnerability in EFS Software Easy Chat Server
CVE-2017-9543
7.5HIGH
What is CVE-2017-9543?
In EFS Software Easy Chat Server versions 2.0 to 3.1, a vulnerability exists that allows remote attackers to reset any user's password by sending a specially crafted POST request to the registresult.htm endpoint. This security flaw can be exploited easily, allowing unauthorized access to user accounts, thereby compromising user data and privacy.
