vendor:
Pagekit CMS
by:
Saurabh Banawar
7,5
CVSS
HIGH
Password Reset Vulnerability
255
CWE
Product Name: Pagekit CMS
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2017
Remote PageKit Password Reset Vulnerability
Anyremote user can reset the password by reading the debug log, the exploit can be successfully executed, if the debug option is enabled in the Pagekit CMS.
Mitigation:
Disable the debug option in the Pagekit CMS.