In langgenius/dify v0.10.1, the `/forgot-password/resets` endpoint does not verify the password reset code, allowing an attacker to reset the password of any user, including administrators. This vulnerability can lead to a complete compromise of the application.
References
Configurations
No configuration.
History
20 Mar 2025, 10:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-20 10:15
Updated : 2025-03-20 10:15
NVD link : CVE-2024-12776
Mitre link : CVE-2024-12776
CVE.ORG link : CVE-2024-12776
JSON object : View
Products Affected
No product.
CWE
CWE-305
Authentication Bypass by Primary Weakness