CVE-2025-12866
BaseFortify
Publication date: 2025-11-10
Last updated on: 2025-11-12
Assigner: TWCERT/CC
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| hundred_plus | eip_plus | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-640 | The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in EIP Plus developed by Hundred Plus involves a weak password recovery mechanism. It allows an unauthenticated remote attacker to predict or brute-force the 'forgot password' link, enabling them to reset any user's password without authorization.
How can this vulnerability impact me? :
An attacker exploiting this vulnerability can gain unauthorized access to user accounts by resetting their passwords. This can lead to loss of confidentiality, integrity, and availability of user data and services, potentially causing significant harm to users and the organization.