CVE-2019-15749 affects SITOS six Build v6.2.1, allowing unauthorized password and recovery email changes without requiring the old password for confirmation. This medium-severity vulnerability (CVSS 6.5) can be exploited via network-based attacks with low complexity, requiring user interaction, leading to high integrity impact. While no active exploitation, public exploit code, or significant community discussion has been observed, the flaw could be leveraged by an attacker with initial access, such as through XSS or an unattended workstation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.2.1CPE matchmatch criteria | cpe:2.3:a:sitos:sitos_six:6.2.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.