Weintek Weincloud v0.13.6 could allow an attacker to reset a password with the corresponding account’s JWT token only.