← Back

CVE-2016-0783

nvd nist
Published: Apr 11, 2016Modified: May 6, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

The sendHashByUser function in Apache OpenMeetings before 3.1.1 generates predictable password reset tokens, which makes it easier for remote attackers to reset arbitrary user passwords by leveraging knowledge of a user name and the current system time.

Affected (1)

Products: Apache: Openmeetings
1 product
Openmeetings
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 3.1.0

Timeline

No history available yet.