RSS   Vulnerabilities for 'Forgot password'   RSS

2022-03-08
 
CVE-2022-26313

NVD-CWE-noinfo
 

 
A vulnerability has been identified in Mendix Forgot Password Appstore module (All versions >= V3.3.0 < V3.5.1). In certain configurations of the affected product, a threat actor could use the sign up flow to hijack arbitrary user accounts.

 
 
CVE-2022-26314

CWE-307
 

 
A vulnerability has been identified in Mendix Forgot Password Appstore module (All versions >= V3.3.0 < V3.5.1), Mendix Forgot Password Appstore module (Mendix 7 compatible) (All versions < V3.2.2). Initial passwords are generated in an insecure manner. This could allow an unauthenticated remote attacker to efficiently brute force passwords in specific situations.

 
2021-03-15
 
CVE-2021-25672

CWE-284
 

 
A vulnerability has been identified in Mendix Forgot Password Appstore module (All Versions < V3.2.1). The Forgot Password Marketplace module does not properly control access. An attacker could take over accounts.

 

 >>> Vendor: Mendix 6 Products
Mendix
Mendixsso
Forgot password
Database replication
SAML
Excel importer


Copyright 2024, cxsecurity.com

 

Back to Top