Vulnerability Description
An issue was discovered in Delta RM 1.2. It is possible to request a new password for any other account using the account ID. Using the /listes/DTsendmaildata/adm_utilisateur/send-mail.json endpoint, a user can send a JSON array with user IDs that will have their passwords reset (and new ones sent to their respective e-mail addresses).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Deltarm | Delta Rm | 1.2 |
Related Weaknesses (CWE)
References
- https://gist.github.com/rntcruz23/16ac2d9dfc7e32b0f57dc7b20f17cd29Third Party Advisory
- https://www.deltarm.comProductVendor Advisory
- https://gist.github.com/rntcruz23/16ac2d9dfc7e32b0f57dc7b20f17cd29Third Party Advisory
- https://www.deltarm.comProductVendor Advisory
FAQ
What is CVE-2021-44839?
CVE-2021-44839 is a vulnerability with a CVSS score of 6.5 (MEDIUM). An issue was discovered in Delta RM 1.2. It is possible to request a new password for any other account using the account ID. Using the /listes/DTsendmaildata/adm_utilisateur/send-mail.json endpoint, ...
How severe is CVE-2021-44839?
CVE-2021-44839 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-44839?
Check the references section above for vendor advisories and patch information. Affected products include: Deltarm Delta Rm.