Metrics
Affected Vendors & Products
Fri, 02 Jan 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 31 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in Uasoft badaso up to 2.9.7. Affected is the function forgetPassword of the file src/Controllers/BadasoAuthController.php of the component Token Handler. Such manipulation leads to weak password recovery. The attack can be executed remotely. This attack is characterized by high complexity. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | Uasoft badaso Token BadasoAuthController.php forgetPassword password recovery | |
| Weaknesses | CWE-640 | |
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-12-31T22:02:08.542Z
Updated: 2026-01-02T14:35:19.486Z
Reserved: 2025-12-31T14:46:12.996Z
Link: CVE-2025-15398
Updated: 2026-01-02T14:15:56.326Z
Status : Awaiting Analysis
Published: 2025-12-31T22:15:48.833
Modified: 2026-01-02T16:45:26.640
Link: CVE-2025-15398
No data.