CVE-2021-44152
Reprise License Manager 14.2 - Authentication Bypass
Record summary
CVE-2021-44152 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
An issue was discovered in Reprise RLM 14.2. Because /goform/change_password_process does not verify authentication or authorization, an unauthenticated user can change the password of any existing user. This allows an attacker to change the password of any known user, thereby preventing valid users from accessing the system and granting the attacker full access to that user's account.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryCRITICALReprise License Manager 14.2 - Authentication BypassCVSS 9.8
Reprise License Manager (RLM) 14.2 does not verify authentication or authorization and allows unauthenticated users to change the password of any existing user.
Impact
Successful exploitation of this vulnerability could allow an attacker to bypass authentication and gain unauthorized access to the Reprise License Manager.
Remediation
Apply the latest security patch or upgrade to a patched version of Reprise License Manager to mitigate this vulnerability.
Source: ProjectDiscovery