Soar Cloud Ltd. HR Portal has a weak Password Recovery Mechanism for Forgotten Password. The reset password link sent out through e-mail, and the link will remain valid after the password has been reset and after the expected expiration date. An attacker with access to the browser history or has the line can thus use the URL again to change the password in order to take over the account.
References
Link Resource
https://www.twcert.org.tw/tw/cp-132-7347-2653e-1.html Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: twcert

Published: 2023-09-07T02:00:15.946Z

Updated: 2023-09-07T02:00:15.946Z

Reserved: 2023-06-02T08:28:37.821Z


Link: CVE-2023-34357

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-09-07T03:15:08.263

Modified: 2023-09-12T11:59:33.197


Link: CVE-2023-34357

JSON object: View

cve-icon Redhat Information

No data.

CWE