CVE-2024-3777

The password reset feature of Ai3 QbiBot lacks proper access control, allowing unauthenticated remote attackers to reset any user's password.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ai3:qbibot:-:*:*:*:*:*:*:*

History

08 Apr 2025, 16:31

Type Values Removed Values Added
First Time Ai3
Ai3 qbibot
CPE cpe:2.3:a:ai3:qbibot:-:*:*:*:*:*:*:*
References () https://www.twcert.org.tw/tw/cp-132-7732-9a54e-1.html - () https://www.twcert.org.tw/tw/cp-132-7732-9a54e-1.html - Third Party Advisory

Information

Published : 2024-04-15 04:15

Updated : 2025-04-08 16:31


NVD link : CVE-2024-3777

Mitre link : CVE-2024-3777

CVE.ORG link : CVE-2024-3777


JSON object : View

Products Affected

ai3

  • qbibot
CWE
CWE-306

Missing Authentication for Critical Function