CVE-2023-49589
HIGHWwbn Avideo - Password Reset Weakness
Title source: ruleDescription
An insufficient entropy vulnerability exists in the userRecoverPass.php recoverPass generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to an arbitrary user password recovery. An attacker can send an HTTP request to trigger this vulnerability.
Scores
CVSS v3
8.8
EPSS
0.0025
EPSS Percentile
47.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-640
Status
published
Affected Products (1)
wwbn/avideo
Timeline
Published
Jan 10, 2024
Tracked Since
Feb 18, 2026