CVE-2019-10014: Medium severity dedecms v6 vulnerability
Published Mar 24, 2019
·Updated
In DedeCMS 5.7SP2, member/resetpassword.php allows remote authenticated users to reset the passwords of arbitrary users via a modified id parameter, because the key parameter is not properly validated.
Affected Software
1 affected component
DedeCMS Dedecms=5.7-sp2
Event History
Mar 24, 2019
CVE Published
via MITRE·09:02 PM
Data Sourced
via MITRE·09:02 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-10014?
CVE-2019-10014 has a CVSS score indicating it is a high-severity vulnerability affecting DedeCMS.
2
How do I fix CVE-2019-10014?
To fix CVE-2019-10014, update to a version of DedeCMS that properly validates the key parameter in password reset requests.
3
Who can exploit CVE-2019-10014?
CVE-2019-10014 can be exploited by remote authenticated users who manipulate the id parameter in the password reset functionality.
4
What versions of DedeCMS are impacted by CVE-2019-10014?
CVE-2019-10014 specifically affects DedeCMS version 5.7SP2.
5
What type of vulnerability is CVE-2019-10014?
CVE-2019-10014 is an access control vulnerability allowing unauthorized password resets.