← back
CVE-2025-56676mediumCWE-1259

CVE-2025-56676

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 5.4epss 0.3%
exploitation probability
0.3%top 77% of all CVEs
observed exploitation
nono source reports it
In short

TitanSystems Zender v3.9.7 has a flaw in its password reset feature where a reset token meant for one user can be used to log into any other user's account. An attacker can take over accounts by exploiting this broken validation, gaining unauthorized access to sensitive information.

Technical detail

The password reset functionality fails to properly validate the linkage between reset tokens and user accounts (CWE-1259: Improper Validation of Specified Quantity in Input). An attacker can intercept or obtain a reset token issued to one user and apply it to another user's account during login, bypassing authentication and achieving account takeover. This enables unauthorized access and privilege escalation without requiring the target user's credentials.

Summary generated and translated by AI from the official description.
TitanSystems Zender v3.9.7 contains an account takeover vulnerability in its password reset functionality. A temporary password or reset token issued to one user can be used to log in as another user, due to improper validation of token-user linkage. This allows remote attackers to gain unauthorized access to any user account by exploiting the password reset mechanism. The vulnerability occurs because the reset token is not correctly bound to the requesting account and is accepted for other user emails during login, enabling privilege escalation and information disclosure.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
Affected products
n/a · n/a