PT-2026-48717 · Penguinmod · Penguinmod-Backendapi
CVE-2026-47181
·
Published
2026-06-11
·
Updated
2026-06-16
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
PenguinMod-BackendApi versions prior to 1.0.0
Description
A NoSQL injection—a method of attacking non-relational databases by manipulating queries—exists in the password reset endpoint. This allows an authenticated user with a registered account and a valid password reset token for their own account to change the password of any other account, resulting in full account takeover.
Recommendations
Update to version 1.0.0.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Penguinmod-Backendapi