CVE-2022-25027

The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authentication and access restricted pages by validating the user's session token when the "Password forgotten?" button is clicked.
Configurations

Configuration 1 (hide)

cpe:2.3:a:rocketsoftware:trufusion_enterprise:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-01-12 23:15

Updated : 2024-02-28 19:51


NVD link : CVE-2022-25027

Mitre link : CVE-2022-25027

CVE.ORG link : CVE-2022-25027


JSON object : View

Products Affected

rocketsoftware

  • trufusion_enterprise
CWE
CWE-640

Weak Password Recovery Mechanism for Forgotten Password