CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 6.5. It may be remotely exploitable. Exploitation may require the attacker to be authenticated.
CVE
CVE-2019-10014
Severity
MEDIUM
CVSS
6.5
EPSS
1.09%
Original NVD Description
In DedeCMS 5.7SP2, member/resetpassword.php allows remote authenticated users to reset the passwords of arbitrary users via a modified id parameter, because the key parameter is not properly validated.
Related CVEs
Other vulnerabilities affecting the same vendor(s)