CyberRota Analysis
AI-GeneratedApache Answer versions up to 2.0.1 are vulnerable due to a missing authorization check in the external-login email binding flow, allowing unauthenticated attackers to hijack user accounts via a crafted confirmation link. Organizations using this software should prioritize upgrading to version 2.0.2 to mitigate the risk of account takeover.
Original NVD Description
Insufficient Verification of Data Authenticity vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing authorization check in the external-login email binding flow allows unauthenticated attackers to take over arbitrary user accounts by tricking victims into clicking a crafted confirmation link. Users are recommended to upgrade to version 2.0.2, which fixes the issue.
Related CVEs
Other vulnerabilities affecting the same vendor(s)