8.7
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Description
SOPlanning is vulnerable to Predictable Generation of Password Recovery Token. Due to weak mechanism of generating recovery tokens, a malicious attacker is able to brute-force all possible values and takeover any account in reasonable amount of time.
This issue was fixed in version 1.55.
This issue was fixed in version 1.55.
Basic Information
ID
CVE-2025-62294
Source
CERT-PL
Published
Nov 20, 2025 at 15:43
Modified
Nov 20, 2025 at 18:59
Affected Product
Vendor
SOPlanning
Product
SOPlanning
Affected Versions
SOPlanning SOPlanning 0