Description
reset-password.php in ProjectSend before r1295 allows remote attackers to reset a password because of incorrect business logic. Errors are not properly considered (an invalid token parameter).
Remediation
References
Related Vulnerabilities
MySQL CVE-2015-4866 Vulnerability (CVE-2015-4866)
WordPress Plugin Namaste! LMS Cross-Site Scripting (2.5.9.3)
Moodle Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2016-2157)
CakePHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-4399)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-0724)