CVE Vulnerabilities

CVE-2025-52338

Authentication Bypass Using an Alternate Path or Channel

Published: Aug 19, 2025 | Modified: Aug 20, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An issue in the default configuration of the password reset function in LogicData eCommerce Framework v5.0.9.7000 allows attackers to bypass authentication and compromise user accounts via a bruteforce attack.

Weakness

The product requires authentication, but the product has an alternate path or channel that does not require authentication.

Potential Mitigations

References