ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-28597”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-28597
Published
2021-03-03
CVSS:
9.8
ShadowTrackr CVSS:
7.2
Summary:
A predictable seed vulnerability exists in the password reset functionality of Epignosis EfrontPro 5.2.21. By predicting the seed it is possible to generate the correct password reset 1-time token. An attacker can visit the password reset supplying the password reset token to reset the password of an account of their choice.