The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authentication and access restricted pages by validating the user's session token when the "Password forgotten?" button is clicked.
Loading...
Loading...
Score 7.5 from GitHub Security Advisory (severity: HIGH) published 2023-01-13. NVD baseline CVSS 7.5; sources differ by 0.0.
The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authentication and access restricted pages by validating the user's session token when the "Password forgotten?" button is clicked.
January 12, 2023
April 8, 2025
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
See which npm, PyPI, Go, and Maven packages are affected by CVE-2022-25027
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.