CVE-2025-3895 Details
Description
Token used for resetting passwords in MegaBIP software are generated using a small space of random values combined with a queryable value. It allows an unauthenticated attacker who know user login names to brute force these tokens and change account passwords (including these belonging to administrators). Version 5.20 of MegaBIP fixes this issue.
A vulnerability in MegaBIP software versions through 5.19 allows an unauthenticated attacker who knows user login names to brute force password reset tokens. These tokens are generated using a limited range of random values combined with a queryable value, enabling the attacker to manipulate the token and reset passwords for any user, including administrators. This vulnerability arises from the predictable token generation method, which creates an opportunity for brute force attacks on the password reset mechanism.
Users are advised to update to MegaBIP version 5.20, which addresses this vulnerability. During the update, it is important to manually replace three files in the editor/config directory, as the automatic updater does not modify this folder. The files to be replaced are include_wysiwyg1.php, include_wysiwyg2.php, and include_wysiwyg3.php.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 23, 2025CISA-ADP
Assessed May 23, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-334 | Small Space of Random Values | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Jan Syski MegaBIP | <= 5.19 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 23, 2025 | New CVE Received | [email protected] |
Volerion