CVE-2025-4552
MEDIUMContinew Admin < 3.6.0 - Password Reset Weakness
Title source: ruleDescription
A vulnerability has been found in ContiNew Admin up to 3.6.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /dev-api/system/user/1/password. The manipulation leads to unverified password change. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Scores
CVSS v3
5.4
EPSS
0.0042
EPSS Percentile
61.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Classification
CWE
CWE-620
CWE-640
Status
published
Affected Products (1)
continew/continew_admin
< 3.6.0
Timeline
Published
May 12, 2025
Tracked Since
Feb 18, 2026