classes/admin.class.php in CubeCart 5.2.12 through 5.2.16 and 6.x before 6.0.7 does not properly validate that a password reset request was made, which allows remote attackers to change the administrator password via a recovery request with a space character in the validate parameter and the administrator email in the email parameter.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T07:36:34.395Z
Reserved: 2015-09-14T00:00:00
Link: CVE-2015-6928

No data.

Status : Deferred
Published: 2015-09-28T15:59:01.627
Modified: 2025-04-12T10:46:40.837
Link: CVE-2015-6928

No data.