Security Advisory

CVE-2014-2269

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2014-04-21 14:00:00
Last updated 2024-08-06 10:06:00
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

modules/Users/ForgotPassword.php in vTiger 6.0 before Security Patch 2 allows remote attackers to reset the password for arbitrary users via a request containing the username, password, and confirmPassword parameters.