Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pc4j-h2fr-9v52

Опубликовано: 16 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 8.3

Описание

zlt2000 microservices-platform through 6.0.0 contains an unverified password change vulnerability in the PUT /users/password endpoint that allows authenticated users to change any account password by omitting the current password check. Attackers can supply an arbitrary user id in the request body and a new password to overwrite credentials of any non-administrator account without verification.

zlt2000 microservices-platform through 6.0.0 contains an unverified password change vulnerability in the PUT /users/password endpoint that allows authenticated users to change any account password by omitting the current password check. Attackers can supply an arbitrary user id in the request body and a new password to overwrite credentials of any non-administrator account without verification.

8.7 High

CVSS4

8.3 High

CVSS3

Дефекты

CWE-620

Связанные уязвимости

CVSS3: 8.3
nvd
2 дня назад

zlt2000 microservices-platform through 6.0.0 contains an unverified password change vulnerability in the PUT /users/password endpoint that allows authenticated users to change any account password by omitting the current password check. Attackers can supply an arbitrary user id in the request body and a new password to overwrite credentials of any non-administrator account without verification.

8.7 High

CVSS4

8.3 High

CVSS3

Дефекты

CWE-620