Vulnerability Description
fpw.php in e107 through 1.0.4 does not check the user_ban field, which makes it easier for remote attackers to reset passwords by sending a pwsubmit request and leveraging access to the e-mail account of a banned user.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| E107 | E107 | <= 1.0.4 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2013-7305?
CVE-2013-7305 is a vulnerability with a CVSS score of 4.3 (MEDIUM). fpw.php in e107 through 1.0.4 does not check the user_ban field, which makes it easier for remote attackers to reset passwords by sending a pwsubmit request and leveraging access to the e-mail account...
How severe is CVE-2013-7305?
CVE-2013-7305 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-7305?
Check the references section above for vendor advisories and patch information. Affected products include: E107 E107.