Vulnerabilities > CVE-2008-5670 - Credentials Management vulnerability in Textpattern 4.0.5

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN

Summary

Textpattern (aka Txp CMS) 4.0.5 does not ask for the old password during a password reset, which makes it easier for remote attackers to change a password after hijacking a session.

Vulnerable Configurations

Part Description Count
Application
Textpattern
1

Common Weakness Enumeration (CWE)