CRITICAL9.1
GHSA-wm7g-rmgg-9837
GeniXCMS Arbitrary User Password Reset Vulnerability
Quick fix
GHSA-wm7g-rmgg-9837 — genix/cms: upgrade to the fixed version with the command below.
composer require genix/cms:^1.1.2Details
forgotpassword.php in GeniXCMS lacks a rate limit, which might allow remote attackers to cause a denial of service (login inability) or possibly conduct Arbitrary User Password Reset attacks via a series of requests.
Are you affected?
Enter the version of the package you're using.