7.5
CVSSv3

CVE-2017-5594

Published: 25/01/2017 Updated: 08/01/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.5 | Impact Score: 5.9 | Exploitability Score: 1.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

An issue exists in Pagekit CMS prior to 1.0.11. In this vulnerability the remote attacker is able to reset the registered user's password, when the debug toolbar is enabled. The password is successfully recovered using this exploit. The SecureLayer7 ID is SL7_PGKT_01.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pagekit pagekit

Exploits

# Exploit Title: Remote PageKit Password Reset Vulnerability # Date:​21-01-2017 # Software Link: pagekitcom/ # Exploit Author: Saurabh Banawar from SecureLayer7​ # Contact: twittercom/​securelayer7 # Website: http​s://securelayer7net​ # Category: webapps 1 Description Anyremote user can reset the password by reading t ...