An issue in the default configuration of the password reset function in LogicData eCommerce Framework v5.0.9.7000 allows attackers to bypass authentication and compromise user accounts via a bruteforce attack.
https://www.logicdata.com/products/webstore-for-erp-ecommerce-integration/
https://github.com/TrustStackSecurity/Advisories/tree/main/CVE-2025-52338