Gestsup

Gestsup

12 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.26%
  • Veröffentlicht 13.02.2024 01:15:08
  • Zuletzt bearbeitet 13.03.2025 20:15:16

A Cross-Site Request Forgery (CSRF) in Gestsup v3.2.46 allows attackers to arbitrarily edit user profile information via a crafted request.

  • EPSS 1.34%
  • Veröffentlicht 26.04.2021 19:15:08
  • Zuletzt bearbeitet 21.11.2024 06:06:04

Gestsup before 3.2.10 allows account takeover through the password recovery functionality (remote). The affected component is the file forgot_pwd.php - it uses a weak algorithm for the generation of password recovery tokens (the PHP uniqueid function...