PT-2026-2277 · Ddsn Interactive · Acora Cms

Published

2026-01-12

·

Updated

2026-01-12

·

CVE-2025-63314

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions DDSN Interactive Acora CMS version 10.7.1
Description A static password reset token used in the password reset function allows attackers to reset user passwords and take over accounts through replay attacks. The vulnerable function is the password reset function.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

CVE-2025-63314

Affected Products

Acora Cms