Vulnerability Details CVE-2022-30028
Dradis Professional Edition before 4.3.0 allows attackers to change an account password via reusing a password reset token.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 40.9%
CVSS Severity
CVSS v3 Score 5.9
CVSS v2 Score 4.3
Products affected by CVE-2022-30028
-
cpe:2.3:a:dradisframework:dradis:2.9.0
-
cpe:2.3:a:dradisframework:dradis:3.1.1
-
cpe:2.3:a:dradisframework:dradis:3.1.2
-
cpe:2.3:a:dradisframework:dradis:3.4.1