First published: Tue Oct 29 2024(Updated: )
A NoSQL injection vulnerability in AquilaCMS 1.409.20 and prior allows unauthenticated attackers to reset user and administrator account passwords via the "Reset password" feature.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
AquilaCMS | <1.409.20 | |
Aquila-cms Aquilacms | <=1.409.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-48573 is considered a critical vulnerability due to the ability of unauthenticated attackers to reset user and administrator passwords.
To fix CVE-2024-48573, update AquilaCMS to version 1.409.21 or later, where the vulnerability has been addressed.
Users of AquilaCMS version 1.409.20 and earlier are affected by CVE-2024-48573.
Attackers can exploit CVE-2024-48573 to reset the passwords of user and administrator accounts without authentication.
No, CVE-2024-48573 can be exploited by unauthenticated attackers, making it particularly dangerous.