Executive brief
DDSN Interactive Acora CMS, a content management system used to build and manage websites, contains a critical flaw in its password reset process. The system uses permanent, unchanging security tokens for password resets that do not expire even after they have been used. This allows an unauthorized person to repeatedly reset any user's password, including administrators, leading to a complete takeover of the website and its data.
Technical details
A vulnerability in the password reset mechanism of DDSN Interactive Acora CMS v10.7.1 stems from the use of static and persistent reset tokens. These tokens are not invalidated upon successful password change and lack a time-based expiration (TTL). An attacker who obtains a valid token—through methods such as log access, interception, or previous compromise—can perform a replay attack to arbitrarily reset user passwords. This flaw enables full account takeover and privilege escalation, potentially affecting administrative accounts. As of the advisory, the vulnerability is confirmed in version 10.7.1.
Affected products
- DDSN Interactive Acora CMS (cm3) 10.7.1
Timeline
- 2026-01-12: advisory: CVE published and CISA-ADP enrichment provided