CVE-2018-16988
Open XDMoD Weak Password Reset Allows Account Takeover
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
An authentication bypass vulnerability exists in Open XDMoD through version 7.5.0, allowing account takeover via a weak password reset mechanism. An attacker can exploit this by performing a brute-force attack on a reset token after a password reset has been initiated. This could lead to unauthorized access to systems