Security Advisory
CVE-2016-9479
7.5
HIGH
Vulnerability Description
The "lost password" functionality in b2evolution before 6.7.9 allows remote attackers to reset arbitrary user passwords via a crafted request.
Published Date
December 2, 2016
Official Source
NIST NVD Advisory