SOPlanning is vulnerable to Predictable Generation of Password Recovery Token. Due to weak mechanism of generating recovery tokens, a malicious attacker is able to brute-force all possible values and takeover any account in reasonable amount of time.

This issue was fixed in version 1.55.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 20 Nov 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Nov 2025 16:00:00 +0000

Type Values Removed Values Added
Description SOPlanning is vulnerable to Predictable Generation of Password Recovery Token. Due to weak mechanism of generating recovery tokens, a malicious attacker is able to brute-force all possible values and takeover any account in reasonable amount of time. This issue was fixed in version 1.55.
Title Predictable Generation of Password Recovery Token
Weaknesses CWE-340
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2025-11-20T18:59:36.982Z

Reserved: 2025-10-10T06:53:21.425Z

Link: CVE-2025-62294

cve-icon Vulnrichment

Updated: 2025-11-20T18:45:12.803Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-20T16:15:59.243

Modified: 2025-11-21T15:13:13.800

Link: CVE-2025-62294

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.