Impact
An issue in the ResetPasswordController.php of Slimkit Plus ThinkSNS+ allows a remote attacker to reset a user's password when the verification code is expired. By using an expired code, the attacker can gain control of the victim’s account, effectively escalating privileges to whatever level the account holds. The vulnerability is a flaw in authentication logic that bypasses the enforcement of code validity periods.
Affected Systems
ThinkSNS+ version 2.4 from Slimkit Plus. No other affected vendor or version lists were provided.
Risk and Exploitability
The vulnerability enables direct account takeover, exposing all data and privileges associated with the compromised account. With a CVSS score of 9.8, this flaw is classified as critical, and the EPSS score of less than 1% indicates a low but nonzero likelihood of exploitation currently. The CVE is not listed in the CISA Known Exploited Vulnerabilities catalog. Attackers must supply an expired verification code, which they could acquire through social engineering or by exploiting other weaknesses in the system. The risk remains high for deployments that rely on ThinkSNS+ for user authentication.
OpenCVE Enrichment