PT-2025-19906 · Peprodev · Peprodev Ultimate Profile Solutions

Kenneth Dunn

·

Published

2025-05-07

·

Updated

2025-05-12

·

CVE-2025-3844

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PeproDev Ultimate Profile Solutions versions 1.9.1 through 7.5.2
Description The issue is related to the lack of proper authentication in the handel ajax req() function, specifically with the change user meta functionality. This allows attackers to set an OTP code and log in with it, enabling unauthenticated attackers to log in as other users on the site, including administrators.
Recommendations For versions 1.9.1 through 7.5.2, consider disabling the handel ajax req() function or restricting access to the change user meta functionality until a patch is available. Additionally, restrict the ability to set OTP codes to authenticated users only to minimize the risk of exploitation.

Fix

Authentication Bypass Using an Alternate Path or Channel

Weakness Enumeration

Related Identifiers

CVE-2025-3844

Affected Products

Peprodev Ultimate Profile Solutions