CVE-2020-14015

HIGH

Naviwebs Navigate Cms - Password Reset Weakness

Title source: rule
STIX 2.1

Description

An issue was discovered in Navigate CMS 2.9 r1433. When performing a password reset, a user is emailed an activation code that allows them to reset their password. There is, however, a flaw when no activation code is supplied. The system will allow an unauthorized user to continue setting a password, even though no activation code was supplied, setting the password for the most recently created user in the system (the user with the highest user id).

Scores

CVSS v3 7.5
EPSS 0.0024
EPSS Percentile 47.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-640
Status published
Products (1)
naviwebs/navigate_cms 2.9 r1433
Published Jun 24, 2020
Tracked Since Feb 18, 2026