CVE-2023-3222

HIGH

Password Recovery plugin for Roundcube 1.2 - Weak Password Recovery Mechanism via Unlimited Token Guessing

Title source: llm
STIX 2.1

Description

Vulnerability in the password recovery mechanism of Password Recovery plugin for Roundcube, in its 1.2 version, which could allow a remote attacker to change an existing user´s password by adding a 6-digit numeric token. An attacker could create an automatic script to test all possible values because the platform has no limit on the number of requests.

Scores

CVSS v3 7.5
EPSS 0.0051
EPSS Percentile 39.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-640
Status published
Products (1)
password_recovery_project/password_recovery 1.2
Published Sep 04, 2023
Tracked Since Feb 18, 2026