漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
phpMyFAQ - Authentication Bypass via Missing Password Reset Token in /api/user/password/update
Vulnerability Description
phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in the password reset endpoint that allows unauthenticated attackers to reset any user account password without token verification or email confirmation. Attackers can enumerate valid usernames, obtain plaintext passwords via email, and achieve complete account takeover including administrative access.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Vulnerability Type
过多认证尝试的限制不恰当
Vulnerability Title
phpMyFAQ 安全漏洞
Vulnerability Description
phpMyFAQ是Thorsten Rinne个人开发者的一个多语言、完全由数据库驱动的常见问题解答系统。 phpMyFAQ 4.1.3之前版本存在安全漏洞,该漏洞源于密码重置端点存在身份验证绕过,使得未经验证攻击者可在无令牌验证或邮件确认的情况下重置任意用户账户密码,导致账户接管。
CVSS Information
N/A
Vulnerability Type
N/A