langgenius/dify
cpe:2.3:a:langgenius:dify:*:*:*:*:node.js:*:*
- v0.10.1
A vulnerability in Langgenius Dify version 0.10.1 allows unauthenticated attackers to exploit the password reset feature by guessing six-digit verification codes. The absence of limits on code guess attempts could lead to the reset of passwords for owners, admins, or other users, potentially compromising the entire application.
Exploitation of this vulnerability could result in unauthorized password resets, allowing attackers to gain access to user accounts, including those of owners and admins.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.