Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22200
HistoryDec 19, 2019 - 5:09 a.m.

Insecure Password Reset

2019-12-1905:09:12
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

0.198 Low

EPSS

Percentile

96.4%

Django uses an insecure password reset mechanism. A remote attacker is able to inject into the password reset form, a malicious email address containing a case transformation of Unicode characters that is equal to the existing user’s email address, which will result in the application sending the password reset token to the attacker for the matched user account.

CPENameOperatorVersion
djangole3.0
djangole1.11.26
djangole2.2.8