CVE-2023-50172

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Jan 10, 2024
Updated: Jan 18, 2024
CWE ID 640

Summary

CVE-2023-50172 is a vulnerability affecting the userRecoverPass.php captcha validation functionality in WWBN AVideo's dev master commit 15fed957fb. The issue permits a bypass to the recovery notification process, enabling an attacker to silently generate a recovery passcode for any user through a carefully crafted HTTP request. This vulnerability poses a significant risk to user accounts and security, as it allows unauthorized access to accounts without the need for user interaction or knowledge of existing passwords.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share