CVE-2015-8267: Dovestones Ad Self Password Reset
Critical severity, CVSS 10.0. EPSS: 2.4% chance of exploitation in the next 30 days.
The PasswordReset.Controllers.ResetController.ChangePasswordIndex method in PasswordReset.dll in Dovestones AD Self Password Reset before 3.0.4.0 allows remote attackers to reset arbitrary passwords via a crafted request with a valid username.
Affected products
- Dovestones Ad Self Password Reset: up to and including 3.0.3.0
Published 2015-12-24. Last modified 2026-06-17.