CVE-2025-13565
BaseFortify
Publication date: 2025-11-23
Last updated on: 2025-11-26
Assigner: VulDB
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| warren-daloyan | inventory_management_system | 1.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-640 | The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a weakness in the password recovery functionality of SourceCodester Inventory Management System 1.0, specifically in the /model/user/resetPassword.php file. An attacker can manipulate this function remotely to perform weak password recovery, potentially allowing unauthorized access.
How can this vulnerability impact me? :
The vulnerability can allow an attacker to exploit the password recovery process remotely, potentially leading to unauthorized access or account compromise. This could result in loss of integrity of user accounts or unauthorized actions within the system.