An issue was discovered in Navigate CMS 2.9 r1433. When performing a password reset, a user is emailed an activation code that allows them to reset their password. There is, however, a flaw when no activation code is supplied. The system will allow an unauthorized user to continue setting a password, even though no activation code was supplied, setting the password for the most recently created user in the system (the user with the highest user id).
References
Link Resource
https://blog.sean-wright.com/navigate-cms/ Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2020-06-24T14:23:32

Updated: 2020-06-24T14:23:32

Reserved: 2020-06-10T00:00:00


Link: CVE-2020-14015

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-06-24T15:15:11.993

Modified: 2020-06-29T23:45:24.143


Link: CVE-2020-14015

JSON object: View

cve-icon Redhat Information

No data.

CWE