An issue in kodbox v.1.52.04 and before allows a remote attacker to obtain sensitive information via the captcha feature in the password reset function.
The product does not properly verify that the source of data or communication is valid.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Kodbox | Kodcloud | * | 1.52.04 (including) |