CVE-2015-8707

CVE-2015-8707

Password reset tokens in Magento CE before 1.9.2.2, and Magento EE before 1.14.2.2 are passed via a GET request and not canceled after use, which allows remote attackers to obtain user passwords via a crafted external service with access to the referrer field.

Source: CVE-2015-8707

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다