CVE-2022-25027

Severity CVSS v4.0:
Pending analysis
Type:
CWE-640 Weak Password Recovery Mechanism for Forgotten Password
Publication date:
12/01/2023
Last modified:
08/04/2025

Description

The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authentication and access restricted pages by validating the user's session token when the "Password forgotten?" button is clicked.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rocketsoftware:trufusion_enterprise:*:*:*:*:*:*:*:* 7.9.5.1 (excluding)