PoC Index

CVE-2021-44152

CRITICAL 9.8EPSS 58.6%

An issue was discovered in Reprise RLM 14.2. Because /goform/change_password_process does not verify authentication or authorization, an unauthenticated user can change the password of any existing user. This allows an attacker to change the password of any known user, thereby preventing valid users from accessing the system and granting the attacker full access to that user's account.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
58.55% chance of exploitation in the next 30 days, 99th percentile
Nuclei
critical · CWE-306
Published
2021-12-13
Updated
2024-08-04

Proof-of-concept exploits (1)

Nuclei templates (1)

References

Related