Weak reset token generation in SeedDMS v6.0.20 and v5.1.7 allows attackers to execute a full account takeover via a brute force attack.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Seeddms | Seeddms | 5.1.7 (including) | 5.1.7 (including) |
Seeddms | Seeddms | 6.0.20 (including) | 6.0.20 (including) |