CVE-2023-26770

TaskCafe 0.3.2 lacks validation in the Cookie value. Any unauthenticated attacker who knows a registered UserID can change the password of that user.
Configurations

No configuration.

History

07 Oct 2024, 19:36

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-284

07 Oct 2024, 17:48

Type Values Removed Values Added
Summary
  • (es) TaskCafe 0.3.2 carece de validación en el valor de la cookie. Cualquier atacante no autenticado que conozca un ID de usuario registrado puede cambiar la contraseƱa de ese usuario.

04 Oct 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-04 19:15

Updated : 2024-10-07 19:36


NVD link : CVE-2023-26770

Mitre link : CVE-2023-26770

CVE.ORG link : CVE-2023-26770


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control