MK-AUTH through 19.01 K4.9 allows CSRF for password changes via the central/executar_central.php?acao=altsenha_princ URI.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2021-01-04T02:05:46

Updated: 2024-08-03T18:16:22.523Z

Reserved: 2021-01-04T00:00:00

Link: CVE-2021-21495

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-01-04T03:15:13.480

Modified: 2021-01-07T19:21:22.417

Link: CVE-2021-21495

cve-icon Redhat

No data.