PenguinMod-BackendApi is the backend api for penguinmod. Prior to version 1.0.0, a NoSQL injection vulnerability in the password reset endpoint allows any authenticated user to change the password of an account, leading to full account takeover. An attacker only needs a registered account and a valid password reset token for their own account. This issue has been patched in version 1.0.0.
Metrics
Affected Vendors & Products
References
History
Thu, 11 Jun 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PenguinMod-BackendApi is the backend api for penguinmod. Prior to version 1.0.0, a NoSQL injection vulnerability in the password reset endpoint allows any authenticated user to change the password of an account, leading to full account takeover. An attacker only needs a registered account and a valid password reset token for their own account. This issue has been patched in version 1.0.0. | |
| Title | PenguinMod-BackendApi: NoSQL Injection in Password Reset Endpoint Allows Account Takeover | |
| Weaknesses | CWE-20 CWE-943 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-11T18:49:14.691Z
Reserved: 2026-05-18T22:07:37.434Z
Link: CVE-2026-47181
No data.
Status : Received
Published: 2026-06-11T19:16:46.280
Modified: 2026-06-11T19:16:46.280
Link: CVE-2026-47181
No data.
OpenCVE Enrichment
No data.