CVE-2020-37172: AVideo Platform 8.1 - Cross Site Request Forgery (Password Reset)
AVideo Platform 8.1 contains a cross-site request forgery vulnerability that allows attackers to reset user passwords by exploiting the password recovery mechanism. Attackers can craft malicious requests to the recoverPass endpoint using the user's recovery token to change account credentials without authentication.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-37172?
CVE-2020-37172 is considered a medium severity vulnerability due to its potential for unauthorized password reset.
How do I fix CVE-2020-37172?
To fix CVE-2020-37172, implement anti-CSRF tokens in the password recovery mechanism to validate requests.
Who is affected by CVE-2020-37172?
CVE-2020-37172 affects users of the AVideo Platform version 8.1.
What type of vulnerability is CVE-2020-37172?
CVE-2020-37172 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.
What does CVE-2020-37172 allow an attacker to do?
CVE-2020-37172 allows an attacker to exploit the password recovery mechanism to reset user passwords.