Soar Cloud Ltd. HR Portal has a weak Password Recovery Mechanism for Forgotten Password. The reset password link sent out through e-mail, and the link will remain valid after the password has been reset and after the expected expiration date. An attacker with access to the browser history or has the line can thus use the URL again to change the password in order to take over the account.
References
Link | Resource |
---|---|
https://www.twcert.org.tw/tw/cp-132-7347-2653e-1.html | Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: twcert
Published: 2023-09-07T02:00:15.946Z
Updated: 2023-09-07T02:00:15.946Z
Reserved: 2023-06-02T08:28:37.821Z
Link: CVE-2023-34357
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-09-07T03:15:08.263
Modified: 2023-09-12T11:59:33.197
Link: CVE-2023-34357
JSON object: View
Redhat Information
No data.
CWE