CVE-2022-25027

The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authentication and access restricted pages by validating the user's session token when the "Password forgotten?" button is clicked.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:rocketsoftware:trufusion_enterprise:*:*:*:*:*:*:*:*

Information

Published : 2023-01-12 15:15

Updated : 2023-01-23 08:50


NVD link : CVE-2022-25027

Mitre link : CVE-2022-25027


JSON object : View

CWE
CWE-640

Weak Password Recovery Mechanism for Forgotten Password

Advertisement

dedicated server usa

Products Affected

rocketsoftware

  • trufusion_enterprise