Vulnerabilities > CVE-2016-9479 - Credentials Management vulnerability in B2Evolution

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
b2evolution
CWE-255

Summary

The "lost password" functionality in b2evolution before 6.7.9 allows remote attackers to reset arbitrary user passwords via a crafted request.

Common Weakness Enumeration (CWE)