
Detailed disclosure of CVE-2025-63314: static, non-expiring password reset token in Acora CMS 10.7.1 enabling account takeover and privilege escalation.
Discovered by Joby Y Daniel from Crowe India
DDSN Interactive cm3 Acora CMS version 10.7.1 contains a security vulnerability in its password reset functionality.
The application uses a static and persistent password reset token that is not invalidated after use and does not expire over time.
This flaw allows an attacker who obtains a valid reset token to reuse it indefinitely, leading to account takeover, including privileged user accounts.