CVE-2025-31380

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Apr 17, 2025
CWE ID 640

Summary

CVE-2025-31380 is a vulnerability affecting the password recovery mechanism in the Paid Videochat Turnkey Site, version n/a through 7.3.11. This issue enables an attacker to exploit the forgotten password functionality and gain unauthorized access to user accounts using weak passwords. The vulnerability's weakness lies in the implementation of the password recovery process, allowing potential attackers to bypass security measures and potentially cause significant data breaches. Attackers can take advantage of this flaw to obtain sensitive information, including login credentials and personal data, putting user privacy at risk. It is essential for site administrators to address this issue by updating their software to the latest version or implementing stronger password recovery mechanisms to mitigate the risk of exploitation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share