CVE-2022-25027
12.01.2023, 23:15
The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authentication and access restricted pages by validating the user's session token when the "Password forgotten?" button is clicked.Enginsight
Vendor | Product | Version |
---|---|---|
rocketsoftware | trufusion_enterprise | 𝑥 < 7.9.5.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-640 - Weak Password Recovery Mechanism for Forgotten PasswordThe software contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.
- CWE-287 - Improper AuthenticationWhen an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.