CVE-2021-25672: High severity mendix vulnerability
Published Mar 15, 2021
·Updated
A vulnerability has been identified in Mendix Forgot Password Appstore module (All Versions < V3.2.1). The Forgot Password Marketplace module does not properly control access. An attacker could take over accounts.
Affected Software
1 affected component
Mendix Forgot Password<3.2.1
Event History
Mar 15, 2021
CVE Published
via MITRE·05:03 PM
Data Sourced
via MITRE·05:03 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-25672?
CVE-2021-25672 is a vulnerability in the Mendix Forgot Password Appstore module that allows attackers to take over accounts.
2
How severe is CVE-2021-25672?
CVE-2021-25672 has a severity rating of 8.8 (high).
3
Which software versions are affected by CVE-2021-25672?
All versions of Mendix Forgot Password Appstore module before V3.2.1 are affected by CVE-2021-25672.
4
How can an attacker exploit CVE-2021-25672?
An attacker can exploit CVE-2021-25672 by taking advantage of the improper access control in the Mendix Forgot Password Appstore module.
5
Is there a fix available for CVE-2021-25672?
Yes, upgrading to version 3.2.1 or newer of the Mendix Forgot Password Appstore module will fix CVE-2021-25672.