CyberRota Analysis
AI-GeneratedAuthenticated users can exploit this vulnerability to change their own passwords without needing to provide the current password, and those with specific permissions can also alter other users' passwords. The impact is significant, as it undermines user account security and could lead to unauthorized access. Organizations with systems that allow user management should prioritize addressing this vulnerability to prevent potential account takeovers.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
The vulnerability allows any authenticated user to change their own password without providing the current password or having an active elevated session. It also allows the attacker to change other users’ passwords if the attacker’s account has Edit users permission (which doesn’t allow changing others’ passwords) and lacks Administrate users permission (which is required to change others’ passwords).