Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Trovebox version <= 4.0.0-rc6 contains a Unsafe password reset token generation vulnerability in user component that can result in Password reset. This attack appear to be exploitable via HTTP request. This vulnerability appears to have been fixed in after commit 742b8ed.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Trovebox user组件安全漏洞
Vulnerability Description
Trovebox是一套开源的图片共享和管理平台。user是其中的一个用户组件。 Trovebox 4.0.0-rc6之前版本中的user组件存在安全漏洞,该漏洞源于程序没有创建安全的密码重置令牌。攻击者可通过发送HTTP请求利用该漏洞重置密码。
CVSS Information
N/A
Vulnerability Type
N/A