CVE-2022-25027

The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authentication and access restricted pages by validating the user's session token when the "Password forgotten?" button is clicked.
Configurations

Configuration 1 (hide)

cpe:2.3:a:rocketsoftware:trufusion_enterprise:*:*:*:*:*:*:*:*

History

23 Jan 2023, 16:50

Type Values Removed Values Added
CWE CWE-640
First Time Rocketsoftware trufusion Enterprise
Rocketsoftware
CPE cpe:2.3:a:rocketsoftware:trufusion_enterprise:*:*:*:*:*:*:*:*
References (MISC) https://labs.nettitude.com/blog/cve-2022-25026-cve-2022-25027-vulnerabilities-in-rocket-trufusion-enterprise/ - (MISC) https://labs.nettitude.com/blog/cve-2022-25026-cve-2022-25027-vulnerabilities-in-rocket-trufusion-enterprise/ - Patch, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

12 Jan 2023, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-01-12 23:15

Updated : 2023-12-10 14:48


NVD link : CVE-2022-25027

Mitre link : CVE-2022-25027

CVE.ORG link : CVE-2022-25027


JSON object : View

Products Affected

rocketsoftware

  • trufusion_enterprise
CWE
CWE-640

Weak Password Recovery Mechanism for Forgotten Password