The change password functionality in Bottomline Webseries Payment Application does not require the old password when users enter a new password, which could allow remote authenticated users to change other users' passwords.
References
Configurations
Information
Published : 2005-01-10 21:00
Updated : 2017-07-10 18:32
NVD link : CVE-2005-0288
Mitre link : CVE-2005-0288
JSON object : View
CWE
Products Affected
bottomline
- webseries_payment_application