CVE-2024-12776
In langgenius/dify v0.10.1, the `/forgot-password/resets` endpoint does not verify the password reset code, allowing an attacker to reset the password of any user, including administrators. This vulnerability can lead to a complete compromise of the application.
Vendor
Product
CWE
Yayın Tarihi
2025-03-20 10:15:30
Güncelleme
2025-07-14 18:18:36
Source Identifier
security@huntr.dev
KEV Date Added
-