Description
A privilege escalation detected in flintcms versions <= 1.1.9 allows account takeover due to blind MongoDB injection in password reset.
Remediation
References
https://hackerone.com/reports/386807
Related Vulnerabilities
CVE-2021-23358 Vulnerability in npm package underscore
CVE-2016-10735 Vulnerability in maven package fr.norad.bootstrap:bootstrap
CVE-2023-49803 Vulnerability in maven package org.webjars.npm:koa__cors
CVE-2020-27543 Vulnerability in npm package restify-paginate
CVE-2023-43123 Vulnerability in maven package org.apache.storm:storm-server