Description
A privilege escalation detected in flintcms versions <= 1.1.9 allows account takeover due to blind MongoDB injection in password reset.
Remediation
References
https://hackerone.com/reports/386807
Related Vulnerabilities
CVE-2016-3081 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2021-44138 Vulnerability in maven package com.caucho:resin
CVE-2022-45389 Vulnerability in maven package com.cloudbees.jenkins.plugins:xpdev
CVE-2022-45598 Vulnerability in npm package @joplin/renderer
CVE-2023-24998 Vulnerability in maven package commons-fileupload:commons-fileupload