CVE-2025-50503 Details
Description
A vulnerability in the password reset workflow of the Touch Lebanon Mobile App 2.20.2 allows an attacker to bypass the OTP reset password mechanism. By manipulating the reset process, an unauthorized user may be able to reset the password and gain access to the account without needing to provide a legitimate authentication factor, such as an OTP. This compromises account security and allows for potential unauthorized access to user data.
A vulnerability exists in the password reset workflow of the Touch Lebanon Mobile App version 2.20.2. This issue allows attackers to bypass the one-time password (OTP) verification required for resetting passwords. By exploiting this flaw, unauthorized users can reset passwords and gain access to accounts without a legitimate authentication factor, such as an OTP. This vulnerability compromises account security and could lead to unauthorized access to user data.
Users are advised to implement proper validation of verification codes during the password reset process. This includes ensuring codes match exactly, implementing expiration times for codes, and invalidating codes after use. Additionally, rate limiting password reset attempts and enhancing security measures for account recovery can help mitigate the risks associated with this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 20, 2025CISA-ADP
Assessed Aug 20, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-640 | Weak Password Recovery Mechanism for Forgotten Password | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Touch Lebanon Mobile App | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 20, 2025 | New CVE Received | [email protected] |
| Aug 20, 2025 | CVE Modified | CISA-ADP |
Volerion