9.8

CVE-2022-44938

Exploit
Weak reset token generation in SeedDMS v6.0.20 and v5.1.7 allows attackers to execute a full account takeover via a brute force attack.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Seeddms ≫ Seeddms Version 5.1.7
Seeddms ≫ Seeddms Version 6.0.20
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.96% 0.569
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA-ADP 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-330 Use of Insufficiently Random Values

The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.

https://pwnit.io/2022/11/23/weak-password-reset-token-leads-to-account-takeover-in-seeddms/
Third Party Advisory
Exploit