Description
EIP Plus developed by Hundred Plus has a Weak Password Recovery Mechanism vulnerability, allowing unauthenticated remote attacker to predict or brute-force the 'forgot password' link, thereby successfully resetting any user's password.
Problem types
CWE-640 Weak Password Recovery Mechanism for Forgotten Password
Product status
Any version before RELEASE_240626
References
www.chtsecurity.com/.../20848f61-9db5-44fd-8574-c9d6a54e4010
www.twcert.org.tw/tw/cp-132-10490-2534b-1.html
www.twcert.org.tw/en/cp-139-10491-004b0-2.html