CVE-2020-26061
HIGHClickStudios Passwordstate < 8.5 - Unauthenticated Authentication Bypass via ResetPassword Function
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-26061. PoCs published by missing0x00.
AI-analyzed exploit summary This PoC exploits an authentication bypass vulnerability in ClickStudios Passwordstate Password Reset Portal before 8.5 build 8501. It allows an unauthenticated attacker to reset the password of any registered user by sending a crafted HTTP request to the /account/ResetPassword endpoint.
Description
ClickStudios Passwordstate Password Reset Portal prior to build 8501 is affected by an authentication bypass vulnerability. The ResetPassword function does not validate whether the user has successfully authenticated using security questions. An unauthenticated, remote attacker can send a crafted HTTP request to the /account/ResetPassword page to set a new password for any registered user.
Exploits (1)
This PoC exploits an authentication bypass vulnerability in ClickStudios Passwordstate Password Reset Portal before 8.5 build 8501. It allows an unauthenticated attacker to reset the password of any registered user by sending a crafted HTTP request to the /account/ResetPassword endpoint.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N