Lighthouse has a new layout. Prefer the old one? Return to the old layout, and switch back any time from the link at the top of each page.

Exponent CMS 2.3.5-Change My Password Vulnerability

#1321

Information

Vulnerability Type : Exponent CMS 2.3.5-Change My Password Vulnerability
Vulnerable Version : 2.3.5
CVE-ID :
Severity: High
Author – Sachin Wagh (@tiger_tigerboy)

Description

Exponent CMS allows to change password without knowing current password.

Credits & Authors
Sachin Wagh (@tiger_tigerboy)

Reported by Sachin Wagh · December 24th, 2015 @ 09:02 AM

State: resolved
Milestone: 2.3.6
Assigned to: dleffler dleffler

Activity

  1. expNinja
    expNinja
    • State changed from new to resolved

    (from [0e476784cc440bea73abe1f065c68fbba699ee59]) Fix issue where admin user can change their own password without entering their current password [#1321 state:resolved] https://github.com/exponentcms/exponent-cms/commit/0e476784cc440bea...

    December 24th, 2015 @ 01:42 PM

Please Sign in or create a free account to add a new ticket.

With your very own profile, you can contribute to projects, track your activity, watch tickets, receive and update tickets through your email and much more.