7.1
CVE-2026-30459
- EPSS 0.31%
- Veröffentlicht 16.04.2026 00:00:00
- Zuletzt bearbeitet 23.04.2026 15:15:23
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
An issue in the Forgot Password feature of Daylight Studio FuelCMS v1.5.2 allows unauthenticated attackers to obtain the password reset token of a victim user via a crafted link placed in a valid e-mail message.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Thedaylightstudio ≫ Fuel Cms Version1.5.2
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.31% | 0.226 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.1 | 2.8 | 4.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N
|
CWE-640 Weak Password Recovery Mechanism for Forgotten Password
The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.
http://daylight.com
http://fuelcms.com
https://github.com/daylightstudio/FUEL-CMS/blob/master/fuel/modules/fuel/controllers/Login.php
https://pentest-tools.com/PTT-2025-029-Password-Reset-Poisoning-via-Host-Header.pdf