Show plain JSON{"id": "CVE-2020-14015", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 5.0, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "LOW", "availabilityImpact": "NONE", "confidentialityImpact": "NONE"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 7.5, "attackVector": "NETWORK", "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "NONE", "confidentialityImpact": "NONE"}, "impactScore": 3.6, "exploitabilityScore": 3.9}]}, "published": "2020-06-24T15:15:11.993", "references": [{"url": "https://blog.sean-wright.com/navigate-cms/", "tags": ["Exploit", "Third Party Advisory"], "source": "cve@mitre.org"}, {"url": "https://blog.sean-wright.com/navigate-cms/", "tags": ["Exploit", "Third Party Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-640"}]}], "descriptions": [{"lang": "en", "value": "An issue was discovered in Navigate CMS 2.9 r1433. When performing a password reset, a user is emailed an activation code that allows them to reset their password. There is, however, a flaw when no activation code is supplied. The system will allow an unauthorized user to continue setting a password, even though no activation code was supplied, setting the password for the most recently created user in the system (the user with the highest user id)."}, {"lang": "es", "value": "Se detect\u00f3 un problema en Navigate CMS versi\u00f3n 2.9 r1433. Al realizar un restablecimiento de contrase\u00f1a, un usuario recibe un correo electr\u00f3nico con un c\u00f3digo de activaci\u00f3n que le permite restablecer su contrase\u00f1a. Sin embargo, se presenta un fallo cuando no se suministra un c\u00f3digo de activaci\u00f3n. El sistema permitir\u00e1 a un usuario no autorizado continuar configurando una contrase\u00f1a, a pesar de que no se proporcion\u00f3 un c\u00f3digo de activaci\u00f3n, configurando la contrase\u00f1a para el usuario creado m\u00e1s recientemente en el sistema (el usuario con el id de usuario m\u00e1s alta)"}], "lastModified": "2024-11-21T05:02:21.377", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:naviwebs:navigate_cms:2.9:r1433:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A1E8C23E-2551-45A4-9F6A-3DD335C2C72F"}], "operator": "OR"}]}], "sourceIdentifier": "cve@mitre.org"}