Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized password resets via the resetPassword API.
References
Configurations
History
No history.
Information
Published : 2024-06-16 16:15
Updated : 2025-03-26 16:15
NVD link : CVE-2024-38468
Mitre link : CVE-2024-38468
CVE.ORG link : CVE-2024-38468
JSON object : View
Products Affected
guoxinled
- synthesis_image_system
CWE
CWE-640
Weak Password Recovery Mechanism for Forgotten Password