What the vulnerability does
01Description
Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions.
Explanation of Vulnerability in Simple Terms
Nokri versions up to 1.6.6 use a weak password recovery mechanism that allows attackers to reset user passwords without proper verification. An attacker can exploit this flaw over the network without authentication to gain unauthorized access to user accounts. The vulnerability affects confidentiality, integrity, and availability of the application.
What an attacker can do
Reset any user's password and take over their account without authentication.
Potential impact on your site
Attackers can compromise any user account, including administrators, leading to full site takeover.
Conditions required to exploit
Network access to the Nokri application; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities