Description
The "lost password" functionality in b2evolution before 6.7.9 allows remote attackers to reset arbitrary user passwords via a crafted request.
Remediation
References
Related Vulnerabilities
OpenVPN AS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2013-2061)
WordPress Plugin OPS Old Post Spinner 'ops_file' Parameter Local File Include (2.2.1)
e107 Other Vulnerability (CVE-2004-2262)
Oracle Database Server CVE-2007-2110 Vulnerability (CVE-2007-2110)
OpenSSL Possible denial of service attack Vulnerability (CVE-2020-1971)