CVE-2025-63314

CRITICAL

DDSN Interactive Acora CMS <10.7.1 - Code Injection

Title source: llm

Description

A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to arbitrarily reset the user password and execute a full account takeover via a replay attack.

Exploits (1)

nomisec WRITEUP
by padayali-JD · poc
https://github.com/padayali-JD/CVE-2025-63314

Scores

CVSS v3 10.0
EPSS 0.0006
EPSS Percentile 17.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L

Details

CWE
CWE-640
Status published
Products (1)
ddsn/cm3_acora_cms 10.7.1
Published Jan 12, 2026
Tracked Since Feb 18, 2026