Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-62294

Опубликовано: 20 нояб. 2025
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

SOPlanning is vulnerable to Predictable Generation of Password Recovery Token. Due to weak mechanism of generating recovery tokens, a malicious attacker is able to brute-force all possible values and takeover any account in reasonable amount of time.

This issue was fixed in version 1.55.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:soplanning:soplanning:*:*:*:*:*:*:*:*
Версия до 1.55.00 (исключая)

EPSS

Процентиль: 14%
0.00046
Низкий

7.5 High

CVSS3

Дефекты

CWE-340

Связанные уязвимости

CVSS3: 7.5
github
3 месяца назад

SOPlanning is vulnerable to Predictable Generation of Password Recovery Token. Due to weak mechanism of generating recovery tokens, a malicious attacker is able to brute-force all possible values and takeover any account in reasonable amount of time. This issue was fixed in version 1.55.

EPSS

Процентиль: 14%
0.00046
Низкий

7.5 High

CVSS3

Дефекты

CWE-340