First published: Fri Apr 15 2022(Updated: )
pearweb < 1.32 is suffers from a Weak Password Recovery Mechanism via include/users/passwordmanage.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Php Pearweb | <1.32.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-27157 is a vulnerability in pearweb < 1.32 that suffers from a weak password recovery mechanism.
CVE-2022-27157 has a severity level of 9.8 (critical).
pearweb < 1.32 is affected by CVE-2022-27157.
To fix CVE-2022-27157, you should update pearweb to version 1.32.0 or above.
More information about CVE-2022-27157 can be found at the following link: [GitHub Commit](https://github.com/pear/pearweb/commit/6447c174a6b4bd76d28ecca8543cbd24bf394f99#diff-204452a70c5b0b0084097fcff6aee77c2c38cb77a41c4b2dd0065fda37a7489c)