PT-2026-67041 · Unknown · Chat On Desk Order Notifications
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Chat On Desk Order Notifications versions prior to 1.0.9
Description
An issue exists when SMS one-time-password password reset is enabled. The software fails to verify that the one-time password has been validated before processing a password-reset request. This allows unauthenticated attackers to reset the password of arbitrary users, including administrators, leading to full account takeover.
Recommendations
Update Chat On Desk Order Notifications to version 1.0.9 or later.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Chat On Desk Order Notifications