cve/2018/CVE-2018-16529.md

18 lines
787 B
Markdown
Raw Normal View History

2024-05-26 14:27:05 +02:00
### [CVE-2018-16529](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16529)
![](https://img.shields.io/static/v1?label=Product&message=Forcepoint%20Email%20Security&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-640%3A%20Weak%20Password%20Recovery%20Mechanism%20for%20Forgotten%20Password&color=brighgreen)
### Description
A password reset vulnerability has been discovered in Forcepoint Email Security 8.5.x. The password reset URL can be used after the intended expiration period or after the URL has already been used to reset a password.
### POC
#### Reference
- https://seclists.org/fulldisclosure/2018/Nov/23
#### Github
No PoCs found on GitHub currently.