vendor:
Easy Chat Server
by:
Aitezaz Mohsin
9
CVSS
CRITICAL
Pre-Auth Remote Password Reset
CWE
Product Name: Easy Chat Server
Affected Version From: v2.0
Affected Version To: v3.1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2017
Easy Chat Server Remote Password Reset
Registeration page 'register.ghp' allows resetting ANY user's password. Remote un-authenticated attackers can send HTTP POST requests to Hijack ANY Easy Chat Server account.