CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 7.5. It may be remotely exploitable.
CVE
CVE-2014-9702
Severity
HIGH
CVSS
7.5
EPSS
1.35%
Original NVD Description
system/classes/DbPDO.php in Cmfive through 2015-03-15, when database connectivity malfunctions, allows remote attackers to obtain sensitive information (username and password) via any request, such as a password reset request.