5.1
CVSSv2

CVE-2010-1910

Published: 12/05/2010 Updated: 10/10/2018
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 454
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

The Forgot Password implementation in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote malicious users to reset passwords of accounts with blank Hint questions and Hint answers by sending an empty value for each of these two Hint fields.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

consona consona dynamic agent -

consona consona live assistance

consona consona subscriber assistance

Exploits

Multiple Consona products suffered from a password reset security bypass vulnerability ...

Mailing Lists

Hi!! 8 years ago, I discovered this vulnerability, CVE-2010-1910, and now, you can see the details cvemitreorg/cgi-bin/cvenamecgi?name=CVE-2010-1910 The login page, "/sdcxuser/asp/loginasp", had a commented access to the page that allowed to change the password of any user, with a link with text "Forgot your password" The link tha ...