PT-2026-27481 · Wallos · Wallos

Tunelko

·

Publicado

2026-03-24

·

Atualizado

2026-03-24

·

CVE-2026-33417

CVSS v3.1

7.1

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Wallos versions prior to 4.7.2
Description Wallos is a personal subscription tracker that allows self-hosting and is open-source. Prior to version 4.7.2, password reset tokens did not expire. The password resets table contains a created at timestamp, but the token validation logic does not verify it. This allows an attacker who intercepts a password reset link to use it indefinitely, even days, weeks, or months after it was initially sent.
Recommendations Update to version 4.7.2 or later.

Exploit

Correção

Insufficient Session Expiration

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-33417
GHSA-P3FV-M43R-3FHF

Produtos afetados

Wallos