Impact
The vulnerability is caused by a weak password recovery mechanism that allows attackers to brute-force the reset code and take over any user account. By repeatedly requesting password reset links or codes, an attacker can guess a valid token and then set a new password, thereby gaining full access to the targeted account. The impact is a compromise of confidentiality, integrity, and availability of the compromised accounts.
Affected Systems
The affected product is AKIN Software’s MyRezzta. Versions from 2.06.03 up to, but not including, 2.07.01 contain the flaw.
Risk and Exploitability
The CVSS score of 9.1 indicates a very high severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, but the lack of mitigation measures such as rate limiting means attackers can successfully exploit the weakness. The likely attack vector is remote through the publicly accessible password reset functionality, requiring no special privileges beyond sending repeated reset requests.
OpenCVE Enrichment