PT-2025-40002 · Titansystems · Zender

Darklotus

·

Published

2025-09-30

·

Updated

2025-12-23

·

CVE-2025-56676

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions TitanSystems Zender version 3.9.7
Description TitanSystems Zender version 3.9.7 has an account takeover issue in its password reset feature. A temporary password or reset token for one user can be used to log in as another user because of incorrect validation of the token-user connection. This allows remote attackers to gain unauthorized access to user accounts by exploiting the password reset mechanism. The issue happens because the reset token is not correctly linked to the account requesting it and is accepted for other user emails during login, enabling privilege escalation and information disclosure.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Weakness Enumeration

Related Identifiers

CVE-2025-56676

Affected Products

Zender