An issue in Olive VLE allows an attacker to obtain sensitive information via the reset password function.
References
Link | Resource |
---|---|
https://medium.com/%40powerful-/account-takeover-ato-via-the-reset-password-cve-2024-48428-84892d6211d6 | Exploit Third Party Advisory |
https://medium.com/h7w/full-account-takeover-via-password-reset-link-manipulation-840fb9402967 | Third Party Advisory |
https://www.linkedin.com/posts/said-al-ghammari-301972285_0day-bugbountytips-bugbountytip-activity-7227418100034412544-2ocu/ | Third Party Advisory |
https://www.olivevle.com/ | Product |
Configurations
History
No history.
Information
Published : 2024-10-25 15:15
Updated : 2025-03-19 19:15
NVD link : CVE-2024-48428
Mitre link : CVE-2024-48428
CVE.ORG link : CVE-2024-48428
JSON object : View
Products Affected
olivegroup
- olivevle
CWE
CWE-640
Weak Password Recovery Mechanism for Forgotten Password