Security Advisory
CVE-2025-12866
9.8
CRITICAL
Vulnerability Description
EIP Plus developed by Hundred Plus has a Weak Password Recovery Mechanism vulnerability, allowing unauthenticated remote attacker to predict or brute-force the 'forgot password' link, thereby successfully resetting any user's password.
Published Date
November 10, 2025
Official Source
NIST NVD Advisory