Pega Infinity Weak Password Recovery Mechanism for Forgotten Password Vulnerability (CVE-2021-27654)
Description
Forgotten password reset functionality for local accounts can be used to bypass local authentication checks.
Forgotten password reset functionality for local accounts can be used to bypass local authentication checks.