Description
reset-password.php in ProjectSend before r1295 allows remote attackers to reset a password because of incorrect business logic. Errors are not properly considered (an invalid token parameter).
Remediation
References
Related Vulnerabilities
XWiki Cleartext Storage of Sensitive Information Vulnerability (CVE-2023-50719)
PHP Numeric Errors Vulnerability (CVE-2008-2107)
ATutor Weak Password Recovery Mechanism for Forgotten Password Vulnerability (CVE-2021-43498)
WordPress Plugin Redux Framework Multiple Cross-Site Scripting Vulnerabilities (3.6.0.2)