CVE-2022-26314
A vulnerability has been identified in Mendix Forgot Password Appstore module (All versions >= V3.3.0 < V3.5.1), Mendix Forgot Password Appstore module (Mendix 7 compatible) (All versions < V3.2.2). Initial passwords are generated in an insecure manner. This could allow an unauthenticated remote attacker to efficiently brute force passwords in specific situations.
- Affected products
- Mendix Forgot Password Appstore Module
- Mendix Forgot Password
- < 3.2.2, 3.5.1
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 1.5% (72th percentile)
- Weakness
- CWE-307
- NVD status
- Modified
- Published
- 2022-03-08
CVE-2022-26314 at NVD
2 known exploits for CVE-2022-26314
Proof-of-concept code and exploit modules indexed by Sploitus