Junglewise Threat Intelligence

CVE-2025-51543: Cicool Builder missing authentication in administrator password reset

CVE-2025-51543 · Severity: critical · CVSS 9.8 · Published 2025-08-19

Executive brief

Cicool Builder, a tool used for generating web pages, forms, and APIs, contains a critical security flaw in its password management system. An unauthorized person can access a specific web address to reset the administrator's password without needing any current credentials. If exploited, this allows a complete takeover of the website, giving the attacker full control over all data and system settings.

Technical details

A missing authentication vulnerability (CWE-306) exists in Cicool Builder versions up to and including 3.4.4. The application fails to enforce proper authorization checks on the '/administrator/auth/reset_password' endpoint. An unauthenticated remote attacker can navigate directly to this URL and reset the administrative password without providing a current password or a valid reset token. Successful exploitation results in a full administrative account takeover and complete compromise of the application and its hosted data. Users are advised to restrict access to administrative endpoints and upgrade to a patched version if available.

Affected products

  • Cicool Cicool Builder <= 3.4.4

Timeline

  • 2025-08-18: disclosed: Vulnerability discovered and PoC created by Yassine Ben Tkhayat
  • 2025-08-19: advisory: CVE published to NVD

References