CVE Database
/

CVE-2015-8267

Back to search

CVE-2015-8267

Published: Dec 24, 2015

Modified: Aug 6, 2024

PUBLISHED

Description

The PasswordReset.Controllers.ResetController.ChangePasswordIndex method in PasswordReset.dll in Dovestones AD Self Password Reset before 3.0.4.0 allows remote attackers to reset arbitrary passwords via a crafted request with a valid username.

VendorProductVersions

n/a

n/a

affected
n/a

References

79642
vdb-entry
x_refsource_BID
VU#757840
third-party-advisory
x_refsource_CERT-VN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now