CVE-2024-48428

An issue in Olive VLE allows an attacker to obtain sensitive information via the reset password function.
Configurations

Configuration 1 (hide)

cpe:2.3:a:olivegroup:olivevle:-:*:*:*:*:*:*:*

History

14 Nov 2024, 23:15

Type Values Removed Values Added
CWE CWE-640
CPE cpe:2.3:a:olivegroup:olivevle:-:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References () https://medium.com/%40powerful-/account-takeover-ato-via-the-reset-password-cve-2024-48428-84892d6211d6 - () https://medium.com/%40powerful-/account-takeover-ato-via-the-reset-password-cve-2024-48428-84892d6211d6 - Exploit, Third Party Advisory
References () https://medium.com/h7w/full-account-takeover-via-password-reset-link-manipulation-840fb9402967 - () https://medium.com/h7w/full-account-takeover-via-password-reset-link-manipulation-840fb9402967 - Third Party Advisory
References () https://www.linkedin.com/posts/said-al-ghammari-301972285_0day-bugbountytips-bugbountytip-activity-7227418100034412544-2ocu/ - () https://www.linkedin.com/posts/said-al-ghammari-301972285_0day-bugbountytips-bugbountytip-activity-7227418100034412544-2ocu/ - Third Party Advisory
References () https://www.olivevle.com/ - () https://www.olivevle.com/ - Product
First Time Olivegroup olivevle
Olivegroup

28 Oct 2024, 13:58

Type Values Removed Values Added
Summary
  • (es) Un problema en Olive VLE permite a un atacante obtener información confidencial a través de la función de restablecimiento de contraseña.

25 Oct 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-25 15:15

Updated : 2024-11-14 23:15


NVD link : CVE-2024-48428

Mitre link : CVE-2024-48428

CVE.ORG link : CVE-2024-48428


JSON object : View

Products Affected

olivegroup

  • olivevle
CWE
CWE-640

Weak Password Recovery Mechanism for Forgotten Password