Security Advisory

CVE-2016-9479

7.5
HIGH

Vulnerability Description

The "lost password" functionality in b2evolution before 6.7.9 allows remote attackers to reset arbitrary user passwords via a crafted request.
Published Date December 2, 2016
Official Source NIST NVD Advisory