Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-29394

Опубликовано: 04 фев. 2022
Источник: nvd
CVSS3: 6.5
CVSS2: 4
EPSS Низкий

Описание

Account Hijacking in /northstar/Admin/changePassword.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote authenticated users to change the password of any targeted user accounts via lack of proper authorization in the user-controlled "userID" parameter of the HTTP POST request.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:globalnorthstar:northstar_club_management:6.3:*:*:*:*:*:*:*

EPSS

Процентиль: 36%
0.00153
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-863

Связанные уязвимости

github
почти 4 года назад

Account Hijacking in /northstar/Admin/changePassword.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote authenticated users to change the password of any targeted user accounts via lack of proper authorization in the user-controlled "userID" parameter of the HTTP POST request.

EPSS

Процентиль: 36%
0.00153
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-863