漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Weak password recovery mechanism in osTicket by Enhancesoft LLC
Vulnerability Description
A logic vulnerability in the password reset token validation routine implemented by osTicket in versions prior to v1.17.8 and v1.18.4. During the password reset process, the application retrieves the timestamp associated with the provided token and checks whether the configured validity period has expired. Consequently, the expiry check is only performed if the timestamp lookup fails, allowing tokens with an existing timestamp to bypass the intended expiry validation. Therefore, an attacker able to obtain a valid password reset token could reuse it to perform an unauthorised password reset and compromise the affected account.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
忘记口令恢复机制弱
Vulnerability Title
Enhancesoft osTicket 授权问题漏洞
Vulnerability Description
Enhancesoft osTicket是美国Enhancesoft公司开源的一套票务系统。 Enhancesoft osTicket v1.17.8之前版本和v1.18.4之前版本存在授权问题漏洞,该漏洞源于密码重置令牌验证例程存在逻辑漏洞,只有在时间戳查找失败时才执行过期检查,导致具有现有时间戳的令牌绕过过期验证,攻击者可能重用有效令牌进行未授权密码重置并危害受影响账户。
CVSS Information
N/A
Vulnerability Type
N/A