Password reset tokens in Magento CE before 1.9.2.2, and Magento EE before 1.14.2.2 are passed via a GET request and not canceled after use, which allows remote attackers to obtain user passwords via a crafted external service with access to the referrer field.
References
Link | Resource |
---|---|
https://magento.com/security/patches/supee-6788 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2017-09-25 18:29
Updated : 2017-10-10 10:50
NVD link : CVE-2015-8707
Mitre link : CVE-2015-8707
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
magento
- magento