Description
A privilege escalation detected in flintcms versions <= 1.1.9 allows account takeover due to blind MongoDB injection in password reset.
Remediation
References
https://hackerone.com/reports/386807
Related Vulnerabilities
CVE-2013-3300 Vulnerability in maven package net.liftweb:lift-json_2.9.1
CVE-2020-28442 Vulnerability in npm package js-data
CVE-2022-31018 Vulnerability in maven package com.typesafe.play:play_2.13
CVE-2022-36437 Vulnerability in maven package com.hazelcast.jet:hazelcast-jet-enterprise
CVE-2021-22134 Vulnerability in maven package org.elasticsearch:elasticsearch