The Forgot Password implementation in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote malicious users to reset passwords of accounts with blank Hint questions and Hint answers by sending an empty value for each of these two Hint fields.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
consona consona_dynamic_agent - |
||
consona consona_subscriber_assistance |
||
consona consona_live_assistance |