CVE-2023-3222
HIGHPassword Recovery - Password Reset Weakness
Title source: ruleDescription
Vulnerability in the password recovery mechanism of Password Recovery plugin for Roundcube, in its 1.2 version, which could allow a remote attacker to change an existing user´s password by adding a 6-digit numeric token. An attacker could create an automatic script to test all possible values because the platform has no limit on the number of requests.
Scores
CVSS v3
7.5
EPSS
0.0006
EPSS Percentile
19.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-640
Status
published
Affected Products (1)
password_recovery_project/password_recovery
Timeline
Published
Sep 04, 2023
Tracked Since
Feb 18, 2026