Authorization Bypass in b2evolution by b2evolution
CVE-2022-30935
9.1CRITICAL
What is CVE-2022-30935?
The b2evolution platform has a security flaw that allows unauthorized remote attackers to exploit a weakness in the password reset functionality. By leveraging a poor randomness function, these attackers can predict password reset tokens for any user. This vulnerability enables them to gain valid session access for arbitrary users and reset their passwords without authentication. The issue has been tested and confirmed in version 7.2.3, and earlier versions may also be susceptible.
References
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
