CyberRota Analysis
AI-GeneratedAn authentication bypass vulnerability in Capgo versions prior to 12.128.2 allows attackers to change user passwords via the password change endpoint without needing current password confirmation. This flaw can lead to permanent account lockout for legitimate users and full account takeover by malicious actors with temporary session access. Organizations using affected versions should prioritize immediate patching to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Capgo before 12.128.2 contains an authentication bypass vulnerability in the password change endpoint that allows attackers to change user passwords without requiring current password confirmation. Attackers with temporary session access can exploit this flaw to permanently lock out legitimate users and achieve full account takeover.