Impact
An issue in the ResetPasswordController.php of Slimkit Plus ThinkSNS+ allows a remote attacker to reset a user's password when the verification code is expired. By using an expired code, the attacker can gain control of the victim’s account, effectively escalating privileges to whatever level the account holds. The vulnerability is a flaw in authentication logic that bypasses the enforcement of code validity periods.
Affected Systems
ThinkSNS+ version 2.4 from Slimkit Plus. No other affected vendor or version lists were provided.
Risk and Exploitability
The vulnerability enables direct account takeover, which can expose all data and privileges associated with the compromised account. No CVSS or EPSS scores are available, and the CVE is not listed in the CISA KEV catalog, but the lack of defined mitigation suggests a high potential for exploitation if the endpoint remains unpatched. Attackers need to supply an expired verification code, which may be obtainable through social engineering or by exploiting other weaknesses in the system. The risk is therefore considered high in environments that rely on ThinkSNS+ for user authentication.
OpenCVE Enrichment