YunzMall Password Recovery Vulnerability in ResetpwdController.php
Vulnerability
A critical vulnerability exists in YunzMall versions through 2.4.2, specifically in the password recovery function of the ResetpwdController.php file. This issue arises from the HTTP POST request handling, where improper manipulation of the password argument enables weak password recovery. The vulnerability can be exploited remotely.
Impact
Exploitation of this vulnerability allows for weak password recovery, potentially leading to unauthorized access.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
0.6exploitability
8.7remediation
0.0relevance
0.0threat
6.4urgency
2.9incentive
5.8Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
