CVE-2022-25027

The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authentication and access restricted pages by validating the user's session token when the "Password forgotten?" button is clicked.
Configurations

Configuration 1

cpe:2.3:a:rocketsoftware:trufusion_enterprise:*:*:*:*:*:*:*:*

Information

Published : 2023-01-12 11:15

Updated : 2023-01-23 04:50


NVD link : CVE-2022-25027

Mitre link : CVE-2022-25027

Products Affected
No products.
CWE
CWE-640

Weak Password Recovery Mechanism for Forgotten Password