Pega Infinity Weak Password Recovery Mechanism for Forgotten Password Vulnerability - CVE-2021-27654 - Vulnerability Database

Pega Infinity Weak Password Recovery Mechanism for Forgotten Password Vulnerability - CVE-2021-27654

High
Reference: CVE-2021-27654
Title: Pega Infinity Weak Password Recovery Mechanism for Forgotten Password Vulnerability
Overview:

Forgotten password reset functionality for local accounts can be used to bypass local authentication checks.