Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Taguette vulnerable to password reset link poisoning
Vulnerability Description
Taguette is an open source qualitative research tool. An issue has been discovered in Taguette versions prior to 1.5.0. It was possible for an attacker to request password reset email containing a malicious link, allowing the attacker to set the email if clicked by the victim. This issue has been patched in version 1.5.0.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Vulnerability Type
系统设置或配置在外部可控制
Vulnerability Title
Taguette 安全漏洞
Vulnerability Description
Taguette是Remi Rampin个人开发者的一个定性研究工具。 Taguette 1.5.0之前版本存在安全漏洞,该漏洞源于攻击者可请求包含恶意链接的密码重置电子邮件,可能导致账户接管。
CVSS Information
N/A
Vulnerability Type
N/A