6.8 Medium
AI Score
Confidence
Low
0.008 Low
EPSS
Percentile
81.6%
Textpattern (aka Txp CMS) 4.0.5 does not ask for the old password during a password reset, which makes it easier for remote attackers to change a password after hijacking a session.
secunia.com/advisories/28793
securityreason.com/securityalert/4786
www.securityfocus.com/archive/1/487483/100/200/threaded
www.securityfocus.com/bid/27606