VYPR
High severity7.5NVD Advisory· Published Jul 12, 2022· Updated Jun 17, 2026

CVE-2022-31257

CVE-2022-31257

Description

A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.31), Mendix Applications using Mendix 8 (All versions < V8.18.18), Mendix Applications using Mendix 9 (All versions < V9.14.0), Mendix Applications using Mendix 9 (V9.12) (All versions < V9.12.2), Mendix Applications using Mendix 9 (V9.6) (All versions < V9.6.12). In case of access to an active user session in an application that is built with an affected version, it’s possible to change that user’s password bypassing password validations within a Mendix application. This could allow to set weak passwords.

Affected products

7
  • cpe:2.3:a:mendix:mendix:*:*:*:*:*:*:*:*
    Range: >=7.0.0,<7.32.31
  • Range: < V7.23.31, < V8.18.18, < V9.14.0, < V9.12.2, < V9.6.12
  • All versions < V7.23.31+ 4 more
    • (no CPE)range: All versions < V7.23.31
    • (no CPE)range: All versions < V8.18.18
    • (no CPE)range: All versions < V9.14.0
    • (no CPE)range: All versions < V9.12.2
    • (no CPE)range: All versions < V9.6.12

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.