CVE-2019-11514
Published Apr 25, 2019
Last updated 4 years ago
Overview
- Description
- User/Command/ConfirmEmailHandler.php in Flarum before 0.1.0-beta.8 mishandles invalidation of user email tokens.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Severity
- HIGH
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-459
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:flarum:flarum:0.1.0:-:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D9EF6C49-5066-4252-8356-6109F26CD021" }, { "criteria": "cpe:2.3:a:flarum:flarum:0.1.0:beta:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D7B3CDA0-6E1A-44EF-96E9-52197EE9BD57" }, { "criteria": "cpe:2.3:a:flarum:flarum:0.1.0:beta2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "29211245-B5E7-4D83-BE77-573D8DF19079" }, { "criteria": "cpe:2.3:a:flarum:flarum:0.1.0:beta3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5122F0A6-28F6-4DF5-89E2-850C67729C59" }, { "criteria": "cpe:2.3:a:flarum:flarum:0.1.0:beta4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3D9BAA2E-3888-4B81-BB41-6053CBEE20DF" }, { "criteria": "cpe:2.3:a:flarum:flarum:0.1.0:beta5:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "637415E5-2EE1-4D2C-BB25-56E59827F060" }, { "criteria": "cpe:2.3:a:flarum:flarum:0.1.0:beta6:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6CB8737B-762D-4ACA-B172-D36F8A93365A" }, { "criteria": "cpe:2.3:a:flarum:flarum:0.1.0:beta7:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "36954DAE-127A-4259-8BB6-99B8EF347348" }, { "criteria": "cpe:2.3:a:flarum:flarum:0.1.0:beta7.1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5A5962B6-2742-46C8-AB55-15E5E6997045" }, { "criteria": "cpe:2.3:a:flarum:flarum:0.1.0:beta7.2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EE5F5C50-C597-4B0A-B048-5F294C1DFE57" } ], "operator": "OR" } ] } ]