Impact
The vulnerability exists in Capgo prior to 12.128.2 not validate the user's current password. Attackers who acquire temporary session access can exploit this flaw to change a user’s password, effectively locking out legitimate users and enabling full account takeover. This is a CWE-620 Authentication Bypass by Missing Credential Validation scenario.
Affected Systems
Capgo installations running any version before 12.128.2 are affected. Users who have not applied the update to 12 risk.
Risk and Exploitability
The CVSS score of 8.7, and the EPSS score of < 1% indicates a low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires only temporary session a user session or use session hijacking techniques. Successful exploitation leads to loss of confidentiality and integrity of user accounts and possible disruption of service.
OpenCVE Enrichment