Description
Contao before 3.5.39 and 4.x before 4.7.3 has a Weak Password Recovery Mechanism for a Forgotten Password.
Remediation
References
Related Vulnerabilities
WordPress Plugin FormLift for Infusionsoft Web Forms SQL Injection (7.5.17)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-2935)
Oracle Database Server Other Vulnerability (CVE-2005-1197)
Invision Power Board version 3.3.4 unserialize PHP code execution
WordPress Plugin 301 Redirects-Easy Redirect Manager Security Bypass (2.40)