CVE-2020-15181: Admin account takeover in Alfresco Reset Password
The Alfresco Reset Password add-on before version 1.2.0 relies on untrusted inputs in a security decision. Intruders can get admin's access to the system using the vulnerability in the project. Impacts all servers where this add-on is installed. The problem is fixed in version 1.2.0
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-15181?
CVE-2020-15181 is a vulnerability in the Alfresco Reset Password add-on before version 1.2.0 that allows intruders to gain admin access to the system.
How does CVE-2020-15181 impact servers?
CVE-2020-15181 impacts all servers where the vulnerable Alfresco Reset Password add-on is installed.
How can an intruder exploit CVE-2020-15181?
An intruder can exploit CVE-2020-15181 by leveraging untrusted inputs in a security decision.
How can I fix CVE-2020-15181?
The vulnerability is fixed in version 1.2.0 of the Alfresco Reset Password add-on, so updating to this version will fix CVE-2020-15181.
What is the severity of CVE-2020-15181?
CVE-2020-15181 has a severity rating of 9.8 (Critical).