March 24, 2023, 3:45 p.m. | ASWIN K V

InfoSec Write-ups - Medium infosecwriteups.com

CVE-2020–10965 : Unauthenticated Admin Password Reset

Hello folks,

A vulnerability was identified in the default admin account’s Login/ResetAdminPassword function, which allows for unauthenticated password resets, possibly allowing an attacker to obtain unauthorised access to the account.

https://rashahacks.com/content/images/size/w1140/2023/02/passwords-2.png

Description:

The vulnerability allows an attacker to modify the password of default admin without any authentication. By accessing the Login/ResetAdminPassword , an attacker can provide an email address associated with the admin account, and a password reset link will be sent to that …

admin-panel bug bounty cve cybersecurity hacking password password reset penetration testing reset

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Information Security Engineers

@ D. E. Shaw Research | New York City

Information Security Manager & ISSO

@ Federal Reserve System | Minneapolis, MN

Forensic Lead

@ Arete | Hyderabad

Lead Security Risk Analyst (GRC)

@ Justworks, Inc. | New York City

Consultant Senior en Gestion de Crise Cyber et Continuité d’Activité H/F

@ Hifield | Sèvres, France