Impact
A flaw in the password recovery function of PbootCMS allows remote manipulation of the username, password, email and checkcode parameters, resulting in weak verification and enabling an attacker to reset credentials without proper authorization. This leads to unauthorized access to user accounts, effectively allowing an account takeover. The weakness is identified as CWE-640, reflecting a weak password recovery procedure.
Affected Systems
The vulnerability impacts PbootCMS version 3.2.12 and earlier. Affected users are those deploying these or earlier releases of the CMS.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. The EPSS score is not provided, but the vulnerability is publicly exploitable and can be triggered remotely, allowing attackers to recover passwords and take over accounts. Since it is not listed in the CISA KEV catalog, there is currently no alert indicating active exploitation, yet the public availability of an exploit increases the likelihood of future attacks.
OpenCVE Enrichment