- Description
- RAGFlow through 0.18.1 allows account takeover because it is possible to conduct successful brute-force attacks against email verification codes to perform arbitrary account registration, login, and password reset. Codes are six digits and there is no rate limiting.
- Source
- cve@mitre.org
- NVD status
- Analyzed
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- cve@mitre.org
- CWE-307
- nvd@nist.gov
- NVD-CWE-noinfo
- Hype score
- Not currently trending
CVE-2025-48187 (CVSS:9.1, CRITICAL) is Awaiting Analysis. RAGFlow through 0.18.1 allows account takeover because it is possible to conduct successful brute-force attacks against ..https://t.co/TVmUdhUEuL #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre
@cracbot
22 May 2025
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-48187 RAGFlow through 0.18.1 allows account takeover because it is possible to conduct successful brute-force attacks against email verification codes to perform arbitrary … https://t.co/8hgO8vAkJy
@CVEnew
17 May 2025
477 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
[CVE-2025-48187: CRITICAL] RAGFlow 0.18.1 vulnerability: Account takeover risk due to lack of email verification code rate limiting, enabling successful brute-force attacks for registration, login, and passw...#cve,CVE-2025-48187,#cybersecurity https://t.co/4jf1abgBq6 https://t.c
@CveFindCom
17 May 2025
28 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:infiniflow:ragflow:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0DBC5B6A-6597-43FA-8B39-591F0DF844D2",
"versionEndIncluding": "0.18.1"
}
],
"operator": "OR"
}
]
}
]