CVE-2021-44839

MEDIUM

Deltarm Delta RM - Password Reset Weakness

Title source: rule
STIX 2.1

Description

An issue was discovered in Delta RM 1.2. It is possible to request a new password for any other account using the account ID. Using the /listes/DTsendmaildata/adm_utilisateur/send-mail.json endpoint, a user can send a JSON array with user IDs that will have their passwords reset (and new ones sent to their respective e-mail addresses).

Scores

CVSS v3 6.5
EPSS 0.0015
EPSS Percentile 35.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-640
Status published
Products (1)
deltarm/delta_rm 1.2
Published Jan 18, 2022
Tracked Since Feb 18, 2026