Account Hijacking in... CVE-2021-29394

4.0 AV AC AU C I A
发布: 2022-02-04
修订: 2024-11-21

Account Hijacking in /northstar/Admin/changePassword.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote authenticated users to change the password of any targeted user accounts via lack of proper authorization in the user-controlled "userID" parameter of the HTTP POST request.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息