CVE-2025-63314
EUVD-2026-191612.01.2026, 17:15
A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to arbitrarily reset the user password and execute a full account takeover via a replay attack.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| ddsn | cm3_acora_cms | 10.7.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration