Password Reset Token Mismanagement in CISA Thorium
CVE-2025-35433
2.3LOW
What is CVE-2025-35433?
The CISA Thorium application contains a vulnerability that fails to correctly invalidate previously used tokens during password reset operations. An attacker in possession of an old token could exploit this flaw, gaining unauthorized access even after the password has been reset. This vulnerability poses a significant risk to the security of user accounts, as it undermines the trust placed in the password reset process. It is essential to upgrade to version 1.1.1 or later to address this issue and enhance user account security.
Affected Version(s)
Thorium 1.0.0 < 1.1.1
Thorium 1.1.1