CVE-2023-49589

HIGH

Wwbn Avideo - Password Reset Weakness

Title source: rule

Description

An insufficient entropy vulnerability exists in the userRecoverPass.php recoverPass generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to an arbitrary user password recovery. An attacker can send an HTTP request to trigger this vulnerability.

Scores

CVSS v3 8.8
EPSS 0.0025
EPSS Percentile 47.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-640
Status published

Affected Products (1)

wwbn/avideo

Timeline

Published Jan 10, 2024
Tracked Since Feb 18, 2026