CVE-2023-5840: Weak Password Recovery Mechanism for Forgotten Password in linkstackorg/linkstack
Published Oct 29, 2023
·Updated
Weak Password Recovery Mechanism for Forgotten Password in GitHub repository linkstackorg/linkstack prior to v4.2.9.
Affected Software
1 affected component
linkstack linkstack<4.2.9
Remediation
Event History
Oct 29, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this weak password recovery mechanism?
The vulnerability ID is CVE-2023-5840.
2
What is the affected software for this vulnerability?
The affected software is Linkstack Linkstack version up to (exclusive) v4.2.9.
3
How severe is the vulnerability CVE-2023-5840?
The severity of the vulnerability CVE-2023-5840 is high with a CVSS score of 8.8.
4
How can I fix the weak password recovery mechanism vulnerability in linkstackorg/linkstack?
To fix the vulnerability, update Linkstack Linkstack to version 4.2.9 or later.
5
Are there any references for further information about this vulnerability?
Yes, you can find more information about the vulnerability CVE-2023-5840 in the following references: [Reference 1](https://huntr.com/bounties/8042d8c3-650e-4c0d-9146-d9ccf6082b30), [Reference 2](https://github.com/linkstackorg/linkstack/commit/fe7b99eae88f9e4c4cd4b00bab372cbf4b584b16).