Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in Navigate CMS 2.9 r1433. When performing a password reset, a user is emailed an activation code that allows them to reset their password. There is, however, a flaw when no activation code is supplied. The system will allow an unauthorized user to continue setting a password, even though no activation code was supplied, setting the password for the most recently created user in the system (the user with the highest user id).
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Naviwebs Navigate CMS 授权问题漏洞
Vulnerability Description
Naviwebs Navigate CMS是美国Naviwebs公司的一套开源的内容管理系统(CMS)。 Naviwebs Navigate CMS 2.9 r1433版本中存在安全漏洞,该漏洞源于程序重置密码时,即使未提供激活码也允许用户继续设置密码。攻击者可利用该漏洞为系统中用户设置密码。
CVSS Information
N/A
Vulnerability Type
N/A