Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:37024
HistorySep 14, 2022 - 6:53 a.m.

Improper Access Control

2022-09-1406:53:31
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15
improper access control
vulnerable software
password reset vulnerability

0.001 Low

EPSS

Percentile

25.3%

typo3/cms is vulnerable to improper access control. The expiration time of a password reset link has never been evaluated, which allows an authenticated attacker to use the password reset link to perform a password reset even if the default expiry time of two hours has been exceeded.

0.001 Low

EPSS

Percentile

25.3%