CVE-2024-2463

Published Mar 21, 2024

Last updated 10 months ago

Overview

Description
Weak password recovery mechanism in CDeX application allows to retrieve password reset token.This issue affects CDeX application versions through 5.7.1.
Source
cvd@cert.pl
NVD status
Analyzed
Products
cdex

Risk scores

CVSS 3.1

Type
Secondary
Base score
8
Impact score
5.9
Exploitability score
2.1
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

cvd@cert.pl
CWE-640

Social media

Hype score
Not currently trending

Configurations