#VU5378 Administrative password reset in Pagekit CMS - CVE-2017-5594
Published: January 25, 2017 / Updated: January 25, 2017
Pagekit CMS
YOOtheme
Description
The vulnerability allows a remote attacker to gain administrative access to vulnerable website.
The vulnerability exists due to incorrect validation of user-supplied data during password reset process, when the debug toolbar is enabled. A remote attacker can send a specially crafted HTTP request and reset administrator’s password.
Successful exploitation of the vulnerability may allow an attacker to gain full access to vulnerable website.