CVE-2016-9479: High severity evolution vulnerability
Published Dec 2, 2016
·Updated
The "lost password" functionality in b2evolution before 6.7.9 allows remote attackers to reset arbitrary user passwords via a crafted request.
Affected Software
1 affected component
b2evolution b2evolution<=6.7.8
Remediation
Patch Available
Patch Available
Event History
Dec 2, 2016
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-9479?
CVE-2016-9479 is considered a high-severity vulnerability due to its potential for unauthorized password resets.
2
How do I fix CVE-2016-9479?
To fix CVE-2016-9479, upgrade b2evolution to version 6.7.9 or later.
3
What impact does CVE-2016-9479 have on b2evolution?
CVE-2016-9479 allows remote attackers to reset arbitrary user passwords, compromising user accounts.
4
Is my b2evolution version affected by CVE-2016-9479?
Any b2evolution version prior to 6.7.9 is affected by CVE-2016-9479.
5
Who is vulnerable to CVE-2016-9479?
Any user of b2evolution versions 6.7.8 and earlier is vulnerable to CVE-2016-9479.