Ushahidi Forgotten Reset Password Security Bypass Vulnerability
BID:56748
Info
Ushahidi Forgotten Reset Password Security Bypass Vulnerability
| Bugtraq ID: | 56748 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 30 2012 12:00AM |
| Updated: | Nov 30 2012 12:00AM |
| Credit: | Timothy D. Morgan |
| Vulnerable: |
Ushahidi Ushahidi 2.2 |
| Not Vulnerable: | |
Discussion
Ushahidi Forgotten Reset Password Security Bypass Vulnerability
Ushahidi is prone to a security-bypass vulnerability.
An attacker may exploit this issue to reset account passwords for arbitrary users which may aid in further attacks.
Versions prior to Ushahidi 2.6.1 are vulnerable.
Ushahidi is prone to a security-bypass vulnerability.
An attacker may exploit this issue to reset account passwords for arbitrary users which may aid in further attacks.
Versions prior to Ushahidi 2.6.1 are vulnerable.
Exploit / POC
Ushahidi Forgotten Reset Password Security Bypass Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
Ushahidi Forgotten Reset Password Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for more details.
Solution:
Updates are available. Please see the references for more details.
References
Ushahidi Forgotten Reset Password Security Bypass Vulnerability
References:
References:
- Fixed Make forgot password tokens use better random token #646 (Ushahidi)
- Make forgot password tokens use better random number gen (Ushahidi )
- Ushahidi Homepage (Ushahidi )
- Vulnerability: Forgotten password challenge guessable (Ushahidi)