CVE-2017-8385
Craft CMS before 2.6.2976 does not prevent modification of the URL in a forgot-password email message.
Craft CMS before 2.6.2976 does not prevent modification of the URL in a forgot-password email message.
MEDIUM · CVSS 5.3
EPSS 0.00284
Monitor
- No active-exploitation, high-EPSS, or public-exploit signals - routine patching cadence
Sigma rules0
YARA rules0