Access Control Flaw in Mendix Forgot Password Appstore Module
CVE-2021-25672
8.8HIGH
Key Information:
- Vendor
Siemens
- Vendor
- CVE Published:
- 15 March 2021
What is CVE-2021-25672?
A significant access control vulnerability has been detected in the Mendix Forgot Password Appstore module, affecting all versions prior to V3.2.1. This flaw allows attackers to exploit inadequate control mechanisms, potentially leading to unauthorized account takeovers. Users of the affected module should review their installation and upgrade to an unaffected version to mitigate risks.
Affected Version(s)
Mendix Forgot Password Appstore module All Versions < V3.2.1