CVE-2022-25027

HIGH

Rocket TRUfusion Enterprise < 7.9.5.1 - Authentication Bypass via Forgotten Password Session Token Validation

Title source: llm
STIX 2.1

Description

The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authentication and access restricted pages by validating the user's session token when the "Password forgotten?" button is clicked.

Scores

CVSS v3 7.5
EPSS 0.0105
EPSS Percentile 59.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-287 CWE-640
Status published
Products (1)
rocketsoftware/trufusion_enterprise < 7.9.5.1
Published Jan 12, 2023
Tracked Since Feb 18, 2026