The password-reset feature in as/index.php in SweetRice CMS before 0.6.7.1 allows remote attackers to modify the administrators password by specifying the administrators e-mail address in the email parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Sweetrice | Basic-cms | 0.6.7.1 (including) | 0.6.7.1 (including) |