CyberRota Analysis
AI-GeneratedThe vulnerability allows unauthenticated attackers to reset passwords and re-enable arbitrary frontend user accounts due to improper handling of invalid input in the invitation controller of the affected extension. This poses a significant security risk, as it can lead to unauthorized access to user accounts. Organizations using version 8.x of the extension should prioritize remediation to mitigate potential account takeovers.
Original NVD Description
The extension's invitation controller fails to stop processing after redirecting on invalid input (missing hash, non-existent, disabled, or deleted users), allowing an unauthenticated attacker to set a new password for and re-enable an arbitrary existing frontend user account. This vulnerability is only present in the 8.x versions of the extension.