CVE-2025-52338

Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.

An issue in the default configuration of the password reset function in LogicData eCommerce Framework v5.0.9.7000 allows attackers to bypass authentication and compromise user accounts via a bruteforce attack.

Published 2025-08-19. Last modified 2026-06-17.