components/com_user/models/reset.php in Joomla! 1.5 through 1.5.5 does not properly validate reset tokens, which allows remote attackers to reset the first enabled user (lowest id) password, typically for the administrator.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Com_user | Joomla | 1.5 (including) | 1.5 (including) |
Com_user | Joomla | 1.5.1 (including) | 1.5.1 (including) |
Com_user | Joomla | 1.5.2 (including) | 1.5.2 (including) |
Com_user | Joomla | 1.5.3 (including) | 1.5.3 (including) |
Com_user | Joomla | 1.5.4 (including) | 1.5.4 (including) |
Com_user | Joomla | 1.5.5 (including) | 1.5.5 (including) |