Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Incorrect access control in the Forgot Your Password function of EMSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a crafted password reset token.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
EMSigner 安全漏洞
Vulnerability Description
EMSigner是印度EMSigner公司的一个电子签名解决方案。 EMSigner v2.8.7版本存在安全漏洞,该漏洞源于Forgot Your Password功能存在访问控制错误漏洞,允许未经身份验证的攻击者通过特制的密码重置令牌访问所有注册用户的帐户,包括具有管理员权限的用户。
CVSS Information
N/A
Vulnerability Type
N/A