An issue in Olive VLE allows an attacker to obtain sensitive information via the reset password function.
References
Link | Resource |
---|---|
https://medium.com/%40powerful-/account-takeover-ato-via-the-reset-password-cve-2024-48428-84892d6211d6 | Exploit Third Party Advisory |
https://medium.com/h7w/full-account-takeover-via-password-reset-link-manipulation-840fb9402967 | Third Party Advisory |
https://www.linkedin.com/posts/said-al-ghammari-301972285_0day-bugbountytips-bugbountytip-activity-7227418100034412544-2ocu/ | Third Party Advisory |
https://www.olivevle.com/ | Product |
Configurations
History
14 Nov 2024, 23:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-640 | |
CPE | cpe:2.3:a:olivegroup:olivevle:-:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
References | () https://medium.com/%40powerful-/account-takeover-ato-via-the-reset-password-cve-2024-48428-84892d6211d6 - Exploit, Third Party Advisory | |
References | () https://medium.com/h7w/full-account-takeover-via-password-reset-link-manipulation-840fb9402967 - Third Party Advisory | |
References | () https://www.linkedin.com/posts/said-al-ghammari-301972285_0day-bugbountytips-bugbountytip-activity-7227418100034412544-2ocu/ - Third Party Advisory | |
References | () https://www.olivevle.com/ - Product | |
First Time |
Olivegroup olivevle
Olivegroup |
28 Oct 2024, 13:58
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
25 Oct 2024, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-10-25 15:15
Updated : 2024-11-14 23:15
NVD link : CVE-2024-48428
Mitre link : CVE-2024-48428
CVE.ORG link : CVE-2024-48428
JSON object : View
Products Affected
olivegroup
- olivevle
CWE
CWE-640
Weak Password Recovery Mechanism for Forgotten Password