CVE-2022-27157: Critical severity php pear vulnerability
Published Apr 15, 2022
·Updated
pearweb < 1.32 is suffers from a Weak Password Recovery Mechanism via include/users/passwordmanage.php.
Affected Software
1 affected component
PHP pearweb<1.32.0
Remediation
Event History
Apr 15, 2022
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is CVE-2022-27157?
CVE-2022-27157 is a vulnerability in pearweb < 1.32 that suffers from a weak password recovery mechanism.
2
How severe is CVE-2022-27157?
CVE-2022-27157 has a severity level of 9.8 (critical).
3
What software is affected by CVE-2022-27157?
pearweb < 1.32 is affected by CVE-2022-27157.
4
How can I fix CVE-2022-27157?
To fix CVE-2022-27157, you should update pearweb to version 1.32.0 or above.
5
Where can I find more information about CVE-2022-27157?
More information about CVE-2022-27157 can be found at the following link: [GitHub Commit](https://github.com/pear/pearweb/commit/6447c174a6b4bd76d28ecca8543cbd24bf394f99#diff-204452a70c5b0b0084097fcff6aee77c2c38cb77a41c4b2dd0065fda37a7489c)