Weak Password Recovery Mechanism in Hossein Material Dashboard
CVE-2025-32486
9.8CRITICAL
What is CVE-2025-32486?
The Hossein Material Dashboard has a vulnerability related to its password recovery mechanism. This flaw enables unauthorized individuals to exploit weak recovery processes, potentially leading to privilege escalation scenarios. This issue affects versions from n/a to 1.4.6 of the Material Dashboard, making it essential for users to be aware and take necessary security measures.
Affected Version(s)
Material Dashboard <= 1.4.6
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Martino Spagnuolo (r3verii) (Patchstack Alliance)