VDB
Sign up
CRITICAL9.1

GHSA-wm7g-rmgg-9837

GeniXCMS Arbitrary User Password Reset Vulnerability

Quick fix

GHSA-wm7g-rmgg-9837 — genix/cms: upgrade to the fixed version with the command below.

composer require genix/cms:^1.1.2

Details

forgotpassword.php in GeniXCMS lacks a rate limit, which might allow remote attackers to cause a denial of service (login inability) or possibly conduct Arbitrary User Password Reset attacks via a series of requests.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/genix/cms
Introduced in: 0Fixed in: 1.1.2
Fixcomposer require genix/cms:^1.1.2

References