Cross-Site Request Forgery Vulnerability in Emergency Password Reset by Andy Moyle
CVE-2024-35648
4.3MEDIUM
What is CVE-2024-35648?
The Emergency Password Reset plugin by Andy Moyle is vulnerable to a Cross-Site Request Forgery (CSRF) attack, which can allow unauthorized actions to be performed without the user's consent. This vulnerability affects all versions from the initial release up to 8.0, making it crucial for users to take preventative measures to secure their systems against potential exploitations.
Affected Version(s)
Emergency Password Reset <= 8.0
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Pedro José Navas Pérez | Patchstack Bug Bounty Program