PT-2021-16885 · Suitecrm · Suitecrm

Published

2021-09-29

·

Updated

2024-03-06

·

CVE-2021-25961

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SuiteCRM versions 7.1.7 through 7.10.31 SuiteCRM versions 7.11-beta through 7.11.20
Description The issue arises from the failure to properly invalidate password reset links associated with a deleted user id, making it possible for account takeover of any newly created user with the same user id.
Recommendations For versions 7.1.7 through 7.10.31, consider temporarily restricting the use of password reset links until a patch is available. For versions 7.11-beta through 7.11.20, consider temporarily restricting the use of password reset links until a patch is available. As a temporary workaround, consider disabling the password reset functionality for deleted user ids to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

BIT-SUITECRM-2021-25961
CVE-2021-25961

Affected Products

Suitecrm