nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-28597 CVE-2020-28597
HIGH
Record summary
CVE-2020-28597 has a selected CVSS score of 7.5 (high).
Description
A predictable seed vulnerability exists in the password reset functionality of Epignosis EfrontPro 5.2.21. By predicting the seed it is possible to generate the correct password reset 1-time token. An attacker can visit the password reset supplying the password reset token to reset the password of an account of their choice.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Epignosis | CVE List | Epignosis eFront LMS 5.2.17, Epignosis eFront LMS 5.2.21 | affected |
References
2talosintelligence.com
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1221