PT-2025-40002 · Titansystems · Zender
Darklotus
·
Published
2025-09-30
·
Updated
2025-12-23
·
CVE-2025-56676
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
TitanSystems Zender version 3.9.7
Description
TitanSystems Zender version 3.9.7 has an account takeover issue in its password reset feature. A temporary password or reset token for one user can be used to log in as another user because of incorrect validation of the token-user connection. This allows remote attackers to gain unauthorized access to user accounts by exploiting the password reset mechanism. The issue happens because the reset token is not correctly linked to the account requesting it and is accepted for other user emails during login, enabling privilege escalation and information disclosure.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zender