Executive brief
Cicool Builder, a tool used for generating web pages, forms, and APIs, contains a critical security flaw in its password management system. An unauthorized person can access a specific web address to reset the administrator's password without needing any current credentials. If exploited, this allows a complete takeover of the website, giving the attacker full control over all data and system settings.
Technical details
A missing authentication vulnerability (CWE-306) exists in Cicool Builder versions up to and including 3.4.4. The application fails to enforce proper authorization checks on the '/administrator/auth/reset_password' endpoint. An unauthenticated remote attacker can navigate directly to this URL and reset the administrative password without providing a current password or a valid reset token. Successful exploitation results in a full administrative account takeover and complete compromise of the application and its hosted data. Users are advised to restrict access to administrative endpoints and upgrade to a patched version if available.
Affected products
- Cicool Cicool Builder <= 3.4.4
Timeline
- 2025-08-18: disclosed: Vulnerability discovered and PoC created by Yassine Ben Tkhayat
- 2025-08-19: advisory: CVE published to NVD