Vulnerability Description
gougucms v4.08.18 was discovered to contain a password reset poisoning vulnerability which allows attackers to arbitrarily reset users' passwords via a crafted packet.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gougucms | Gougucms | 4.08.18 |
Related Weaknesses (CWE)
References
- https://gitee.com/gouguopen/gougucms/issues/I88TKHExploitIssue TrackingThird Party Advisory
- https://gitee.com/gouguopen/gougucms/issues/I88TKHExploitIssue TrackingThird Party Advisory
FAQ
What is CVE-2023-46393?
CVE-2023-46393 is a vulnerability with a CVSS score of 7.5 (HIGH). gougucms v4.08.18 was discovered to contain a password reset poisoning vulnerability which allows attackers to arbitrarily reset users' passwords via a crafted packet.
How severe is CVE-2023-46393?
CVE-2023-46393 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-46393?
Check the references section above for vendor advisories and patch information. Affected products include: Gougucms Gougucms.