CVE-2025-63314 - Improper Password Reset Token Handling in Acora CMS
Discovered by Joby Y Daniel from Crowe India
📌 Overview
DDSN Interactive cm3 Acora CMS version 10.7.1 contains a security vulnerability in its password reset functionality.
The application uses a static and persistent password reset token that is not invalidated after use and does not expire over time.
This flaw allows an attacker who obtains a valid reset token to reuse it indefinitely, leading to account takeover, including privileged user accounts.
🛠 Affected Product
- Product Name: cm3 Acora CMS
- Vendor: DDSN Interactive
- Affected Version: 10.7.1
- Component: Password Reset Mechanism
⚠ Vulnerability Details
Root Cause
- Password reset tokens:
- Are static and persistent
- Are not revoked after successful password reset
- Do not expire after a defined time window
Impact
- Reuse of password reset token
- Account takeover
- Privilege escalation
- Unauthorised access
🎯 Attack Scenario
- Attacker obtains a valid password reset token (via logs, email compromise, interception, or insider access).
- The token remains valid indefinitely.
- The attacker reuses the same token multiple times.
- Passwords of users (including administrators) can be reset without detection.