PT-2026-1925 · Unknown · Flaming Password Reset

Published

2026-01-08

·

Updated

2026-01-08

·

CVE-2025-68875

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Flaming Password Reset versions through 1.0.3
Description The software contains an Improper Neutralization of Input During Web Page Generation issue, specifically a Stored Cross-site Scripting (XSS) condition. This allows for the injection of malicious scripts into web pages. The affected component is the flaming-password-reset functionality. The issue allows for Stored XSS, meaning the malicious script is persistently stored on the target server.
Recommendations Flaming Password Reset versions prior to and including 1.0.3 should be updated to a newer, secure version if available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-68875

Affected Products

Flaming Password Reset