← Back to CVE search

CVE-2026-48902

Unknown

Description

The password and username reset features created plain http links for https connections if the -Force SSL- flag wasn-t explicitly set.

CVSS 9.8EPSS 0.252%Risk 1
View source
Published
2026-05-26 17:16:54
Affected versions
unknown
Type
Other
Last modified
2026-07-24 11:10:00
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H