CVE-2017-8385

Publication date

2017-05-01 06:08:00

Family

mitre

State

PUBLISHED

Description

Craft CMS before 2.6.2976 does not prevent modification of the URL in a forgot-password email message.