CVE-2016-0783
The sendHashByUser function in Apache OpenMeetings before 3.1.1 generates predictable password reset tokens, which makes it easier for remote attackers to reset arbitrary user passwords by leveraging knowledge of a user name and the current system time.
Date published : 2016-04-11
http://www.securityfocus.com/archive/1/537886/100/0/threaded