Craft CMS Weak Password Recovery Mechanism for Forgotten Password Vulnerability - CVE-2017-8385 - Vulnerability Database

Craft CMS Weak Password Recovery Mechanism for Forgotten Password Vulnerability - CVE-2017-8385

Medium
Reference: CVE-2017-8385
Title: Craft CMS Weak Password Recovery Mechanism for Forgotten Password Vulnerability
Overview:

Craft CMS before 2.6.2976 does not prevent modification of the URL in a forgot-password email message.