CVE-2022-25027

The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authentication and access restricted pages by validating the user's session token when the "Password forgotten?" button is clicked.
Configurations

Configuration 1 (hide)

cpe:2.3:a:rocketsoftware:trufusion_enterprise:*:*:*:*:*:*:*:*

History

21 Nov 2024, 06:51

Type Values Removed Values Added
Summary
  • (es) La funcionalidad de contraseña olvidada de Rocket TRUfusion Portal v7.9.2.1 permite a atacantes remotos evitar la autenticación y acceder a páginas restringidas validando el token de sesión del usuario cuando se hace clic en el boton "¿Olvidó su contraseña?".
References () https://labs.nettitude.com/blog/cve-2022-25026-cve-2022-25027-vulnerabilities-in-rocket-trufusion-enterprise/ - Patch, Third Party Advisory () https://labs.nettitude.com/blog/cve-2022-25026-cve-2022-25027-vulnerabilities-in-rocket-trufusion-enterprise/ - Patch, Third Party Advisory

Information

Published : 2023-01-12 23:15

Updated : 2024-11-21 06:51


NVD link : CVE-2022-25027

Mitre link : CVE-2022-25027

CVE.ORG link : CVE-2022-25027


JSON object : View

Products Affected

rocketsoftware

  • trufusion_enterprise
CWE
CWE-640

Weak Password Recovery Mechanism for Forgotten Password