CVE-2025-35433 - CISA Thorium does not properly invalidate previously used tokens
CVE ID : CVE-2025-35433
Published : Sept. 17, 2025, 5:15 p.m. | 54 minutes ago
Description : CISA Thorium does not properly invalidate previously used tokens when resetting passwords. An attacker that possesses a previously used token could still log in after a password reset. Fixed in 1.1.1.
Severity: 5.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 17, 2025, 5:15 p.m. | 54 minutes ago
Description : CISA Thorium does not properly invalidate previously used tokens when resetting passwords. An attacker that possesses a previously used token could still log in after a password reset. Fixed in 1.1.1.
Severity: 5.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...