CVE-2020-25728: High severity alfresco reset password vulnerability
The Reset Password add-on before 1.2.0 for Alfresco has a broken algorithm (involving an increment) that allows a malicious user to change any user's account password include the admin account.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-25728?
CVE-2020-25728 is a vulnerability in the Reset Password add-on before version 1.2.0 for Alfresco, allowing a malicious user to change any user's account password, including the admin account.
What is the severity of CVE-2020-25728?
CVE-2020-25728 has a severity rating of 8.8 (high).
How can I fix CVE-2020-25728?
To fix CVE-2020-25728, update your Reset Password add-on to version 1.2.0 or higher for Alfresco.
Where can I find more information about CVE-2020-25728?
You can find more information about CVE-2020-25728 at the following link: [https://amriunix.com/post/alfresco-reset-password-add-on-0-day-vulnerabilities/]
What is CWE-640?
CWE-640 refers to Improper Timestamp Validation, which is the weakness associated with CVE-2020-25728. It involves the use of an incorrect timestamp to validate a resource.