RSS   Vulnerabilities for 'Efront'   RSS

2021-03-03
 
CVE-2020-28597

CWE-335
 

 
A predictable seed vulnerability exists in the password reset functionality of Epignosis EfrontPro 5.2.21. By predicting the seed it is possible to generate the correct password reset 1-time token. An attacker can visit the password reset supplying the password reset token to reset the password of an account of their choice.

 

 >>> Vendor: Epignosishq 2 Products
Efront
Efront lms


Copyright 2024, cxsecurity.com

 

Back to Top