RAGFlow through 0.18.1 allows account takeover because it is possible to conduct successful brute-force attacks against email verification codes to perform arbitrary account registration, login, and password reset. Codes are six digits and there is no rate limiting.
History

Thu, 12 Jun 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Infiniflow
Infiniflow ragflow
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:infiniflow:ragflow:*:*:*:*:*:*:*:*
Vendors & Products Infiniflow
Infiniflow ragflow

Mon, 19 May 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 17 May 2025 12:45:00 +0000

Type Values Removed Values Added
Description RAGFlow through 0.18.1 allows account takeover because it is possible to conduct successful brute-force attacks against email verification codes to perform arbitrary account registration, login, and password reset. Codes are six digits and there is no rate limiting.
Weaknesses CWE-307
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-05-17T00:00:00.000Z

Updated: 2025-05-19T15:56:53.263Z

Reserved: 2025-05-16T00:00:00.000Z

Link: CVE-2025-48187

cve-icon Vulnrichment

Updated: 2025-05-19T15:56:40.486Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-17T13:15:47.750

Modified: 2025-06-12T16:29:12.860

Link: CVE-2025-48187

cve-icon Redhat

No data.