Medium
CVSS 6.8
Overview
Textpattern (aka Txp CMS) 4.0.5 does not ask for the old password during a password reset, which makes it easier for remote attackers to change a password after hijacking a session.
Textpattern (aka Txp CMS) 4.0.5 does not ask for the old password during a passw...
Textpattern (aka Txp CMS) 4.0.5 does not ask for the old password during a password reset, which makes it easier for remote attackers to change a password after hijacking a session.
This vulnerability is rated 🟡 MEDIUM.
Recommended actions: