CVE-2023-3222

Severity CVSS v4.0:
Pending analysis
Type:
CWE-640 Weak Password Recovery Mechanism for Forgotten Password
Publication date:
04/09/2023
Last modified:
08/09/2023

Description

Vulnerability in the password recovery mechanism of Password Recovery plugin for Roundcube, in its 1.2 version, which could allow a remote attacker to change an existing user´s password by adding a 6-digit numeric token. An attacker could create an automatic script to test all possible values because the platform has no limit on the number of requests.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:password_recovery_project:password_recovery:1.2:*:*:*:*:roundcube:*:*