CVE-2024-12776 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

In langgenius/dify v0.10.1, the `/forgot-password/resets` endpoint does not verify the password reset code, allowing an attacker to reset the password of any us…
High CVSS: 8.1

CVE-2024-12776

In langgenius/dify v0.10.1, the `/forgot-password/resets` endpoint does not verify the password reset code, allowing an attacker to reset the password of any user, including administrators. This vulnerability can lead to a complete compromise of the application.
Vendor
Langgenius
Product
Dify
CWE
CWE-305
Yayın Tarihi
2025-03-20 10:15:30
Güncelleme
2025-07-14 18:18:36
Source Identifier
security@huntr.dev
KEV Date Added
-

Kategoriler

Referanslar