Showing 2 vulnerabilities on this page for MSN Password Recovery

Signals CISA KEV Ransomware Nuclei
Top Password Software vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

MSN Password Recovery 1.30 - Denial of Service

MSN Password Recovery version 1.30 contains a denial of service vulnerability that allows attackers to crash the application by supplying an oversized input in the registration code field. Attackers can generate a 9000-byte buffer of repeated characters and paste it into the 'User Name and Registration Code' field to trigger an application crash.

CWE-120Feb 11, 2026
CVSS4.6v4.0EPSS0.231%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

MSN Password Recovery 1.30 - XML External Entity Injection

MSN Password Recovery 1.30 contains an XML external entity injection vulnerability that allows attackers to read local system files through crafted XML input. Attackers can exploit the 'Favorites' tab by injecting a malicious XML file that references external entities to retrieve sensitive system configuration information.

CWE-611Feb 11, 2026
CVSS6.7v4.0EPSS0.207%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX