CVE-2020-25566

CRITICAL

SapphireIMS 5.0 - Unauthenticated Account Takeover via Save_Password Form

Title source: llm
STIX 2.1

Description

In SapphireIMS 5.0, it is possible to take over an account by sending a request to the Save_Password form as shown in POC. Notice that we do not require a JSESSIONID in this request and can reset any user’s password by changing the username to that user and password to base64(desired password).

References (2)

Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://vuln.shellcoder.party/tags/sapphireims/

Scores

CVSS v3 9.8
EPSS 0.0156
EPSS Percentile 72.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-306
Status published
Products (1)
sapphireims/sapphireims 5.0
Published Aug 11, 2021
Tracked Since Feb 18, 2026