PT-2026-65800 · Gridbox · Gridbox
CVSS v4.0
10
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red |
Name of the Vulnerable Software and Affected Versions
Gridbox versions prior to 2.20.2
Description
An issue exists in the
resetPassword() method that allows unauthenticated actors to reset the password of any user, enabling them to log in and perform actions as those users, with the exception of super administrators.Recommendations
Update Gridbox to version 2.20.2 or later.
As a temporary workaround, restrict access to the
resetPassword() method until the update is applied.Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gridbox