PT-2025-47340 · Unknown · Openml.Org Web Application

Published

2025-11-18

·

Updated

2025-11-19

·

CVE-2025-55796

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions openml/openml.org web application version v2.0.20241110
Description The web application generates predictable tokens based on MD5 hashing for critical user actions, including signup confirmation, password resets, email confirmation resends, and email change confirmation. These tokens are created by hashing the current timestamp formatted as "%d %H:%M:%S" without user-specific data or cryptographic randomness. This predictability allows attackers to brute-force valid tokens within a short timeframe, potentially enabling unauthorized account confirmation, password resets, and email change approvals, which could lead to account takeover.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-55796
GHSA-XFJH-GF9P-8QR6

Affected Products

Openml.Org Web Application