← Back to CVE List

CVE-2020-27408

Published: 2020-12-04T16:15Z
Last Modified: 2024-11-21T05:21Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
OpenSIS Community Edition through 7.6 is affected by incorrect access controls for the file ResetUserInfo.php that allow an unauthenticated attacker to change the password of arbitrary users. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt