Soar Cloud Ltd. HR Portal has a weak Password Recovery Mechanism for Forgotten Password. The reset password link sent out through e-mail, and the link will remain valid after the password has been reset and after the expected expiration date. An attacker with access to the browser history or has the line can thus use the URL again to change the password in order to take over the account.
History

Thu, 26 Sep 2024 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2023-09-07T02:00:15.946Z

Updated: 2024-09-26T19:50:30.068Z

Reserved: 2023-06-02T08:28:37.821Z

Link: CVE-2023-34357

cve-icon Vulnrichment

Updated: 2024-08-02T16:10:06.630Z

cve-icon NVD

Status : Analyzed

Published: 2023-09-07T03:15:08.263

Modified: 2023-09-12T11:59:33.197

Link: CVE-2023-34357

cve-icon Redhat

No data.