First published: Wed Jun 24 2020(Updated: )
An issue was discovered in Navigate CMS 2.9 r1433. When performing a password reset, a user is emailed an activation code that allows them to reset their password. There is, however, a flaw when no activation code is supplied. The system will allow an unauthorized user to continue setting a password, even though no activation code was supplied, setting the password for the most recently created user in the system (the user with the highest user id).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Naviwebs Navigate CMS | =2.9-r1433 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-14015.
The severity of CVE-2020-14015 is high, with a severity value of 7.5.
The affected software of CVE-2020-14015 is Navigate CMS version 2.9 r1433.
The exploitability of CVE-2020-14015 is relatively easy.
Yes, a fix is available for CVE-2020-14015. It is recommended to update to a patched version of Navigate CMS.