vendor:
Pligg
by:
SecurityFocus
7.5
CVSS
HIGH
Security Bypass
287
CWE
Product Name: Pligg
Affected Version From: 9.5
Affected Version To: 9.5
Patch Exists: Yes
Related CWE: N/A
CPE: a:pligg:pligg
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008
Pligg Security Bypass Vulnerability
Pligg is prone to a security-bypass vulnerability due to a design error when resetting forgotten passwords. An attacker may exploit this issue to reset account passwords for arbitrary users and then compromise a vulnerable application. This can also aid the attacker in further attacks.
Mitigation:
Ensure that the application is updated to the latest version.