CVE-2015-10057 is a critical improper access controls vulnerability affecting Little Apps Little Software Stats, specifically within the password reset handler in inc/class.securelogin.php. This vulnerability carries a CVSS score of 9.8, indicating a critical severity with a network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While the attack complexity is rated as high and exploitation appears difficult, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage. Upgrading to version 0.2 addresses this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.2CPE matchmatch criteria | cpe:2.3:a:little-apps:little_software_stats:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.