CVE-2021-25961
HIGHSalesagility Suitecrm < 7.10.32 - Password Reset Weakness
Title source: ruleDescription
In “SuiteCRM” application, v7.1.7 through v7.10.31 and v7.11-beta through v7.11.20 fail to properly invalidate password reset links that is associated with a deleted user id, which makes it possible for account takeover of any newly created user with the same user id.
References (3)
Scores
CVSS v3
8.0
EPSS
0.0033
EPSS Percentile
56.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-640
Status
published
Products (1)
salesagility/suitecrm
7.1.7 - 7.10.32
Published
Sep 29, 2021
Tracked Since
Feb 18, 2026