Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2023-49589

An insufficient entropy vulnerability exists in the userRecoverPass.php recoverPass generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted HTTP request can lead to an arbitrary user password recovery. An attacker can send an HTTP request to trigger this vulnerability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 47.9%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2023-49589
  • Wwbn » Avideo » Version: 15fed957fb
    cpe:2.3:a:wwbn:avideo:15fed957fb


Contact Us

Shodan ® - All rights reserved