CVE-2017-8827

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
08/05/2017
Last modified:
20/04/2025

Description

forgotpassword.php in GeniXCMS 1.0.2 lacks a rate limit, which might allow remote attackers to cause a denial of service (login inability) or possibly conduct Arbitrary User Password Reset attacks via a series of requests.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:genixcms:genixcms:1.0.2:*:*:*:*:*:*:*