CVE-2023-49589

HIGH

Wwbn Avideo - Password Reset Weakness

Title source: rule
STIX 2.1

Description

An insufficient entropy vulnerability exists in the userRecoverPass.php recoverPass generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to an arbitrary user password recovery. An attacker can send an HTTP request to trigger this vulnerability.

Scores

CVSS v3 8.8
EPSS 0.0025
EPSS Percentile 47.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-640
Status published
Products (1)
wwbn/avideo 15fed957fb
Published Jan 10, 2024
Tracked Since Feb 18, 2026