The sendHashByUser function in Apache OpenMeetings before 3.1.1 generates predictable password reset tokens, which makes it easier for remote attackers to reset arbitrary user passwords by leveraging knowledge of a user name and the current system time.
References
Configurations
Information
Published : 2016-04-11 07:59
Updated : 2018-10-09 12:58
NVD link : CVE-2016-0783
Mitre link : CVE-2016-0783
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
apache
- openmeetings