Description
The POST /studiocms_api/dashboard/create-reset-link endpoint allows any authenticated user with admin privileges to generate a password reset token for any other user, including the owner account.
Recommendation
Update the studiocms package to the latest compatible version. Followings are version details:
- Affected version(s): <= 0.4.2
- Patched version(s): 0.4.3
References
Could your website be exposed too?
SmartScanner can check your website for StudioCMS: IDOR — Admin-to-Owner Account Takeover via Password Reset Link Generation and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Payload: Pre-Authentication Account Takeover via Parameter Injection in Password Recovery - CVE-2026-34751
- Payload: Pre-Authentication Account Takeover via Parameter Injection in Password Recovery - payload - CVE-2026-34751
- StudioCMS REST getUsers Exposes Owner Account Records to Admin Tokens - CVE-2026-32638
- StudioCMS has Privilege Escalation via Insecure API Token Generation - CVE-2026-30944


