missing0x00/CVE-2020-26061

missing0x00/CVE-2020-26061

Releases0
CVE-2020-26061 - ClickStudios Passwordstate Password Reset Portal

CVE History

CVEPublishedCVSS v3CVSS v2
7.5 HIGH5 MEDIUM

ClickStudios Passwordstate Password Reset Portal prior to build 8501 is affected by an authentication bypass vulnerability. The ResetPassword function does not validate whether the user has successfully authenticated using security questions. An unauthenticated, remote attacker can send a crafted HTTP request to the /account/ResetPassword page to set a new password for any registered user.