Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9g5v-hmcj-pxrc

Опубликовано: 12 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 10

Описание

A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to arbitrarily reset the user password and execute a full account takeover via a replay attack.

A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to arbitrarily reset the user password and execute a full account takeover via a replay attack.

EPSS

Процентиль: 16%
0.0005
Низкий

10 Critical

CVSS3

Дефекты

CWE-640

Связанные уязвимости

CVSS3: 10
nvd
27 дней назад

A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to arbitrarily reset the user password and execute a full account takeover via a replay attack.

EPSS

Процентиль: 16%
0.0005
Низкий

10 Critical

CVSS3

Дефекты

CWE-640