A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to arbitrarily reset the user password and execute a full account takeover via a replay attack.
References
| Link | Resource |
|---|---|
| http://acora.com | Not Applicable |
| http://ddsn.com | Product |
| https://github.com/padayali-JD/CVE-2025-63314 | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-01-12 17:15
Updated : 2026-01-22 22:02
NVD link : CVE-2025-63314
Mitre link : CVE-2025-63314
CVE.ORG link : CVE-2025-63314
JSON object : View
Products Affected
ddsn
- cm3_acora_cms
CWE
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
