### [CVE-2025-29995](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-29995) ![](https://img.shields.io/static/v1?label=Product&message=CAP%20back%20office%20application&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=%3C2.0.4%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-640%20Weak%20Password%20Recovery%20Mechanism%20for%20Forgotten%20Password&color=brightgreen) ### Description This vulnerability exists in the CAP back office application due to a weak password-reset mechanism implemented at API endpoints. An authenticated remote attacker with a valid login ID could exploit this vulnerability through vulnerable API endpoint which could lead to account takeover of targeted users. ### POC #### Reference No PoCs from references. #### Github - https://github.com/fkie-cad/nvd-json-data-feeds