Description

Soar Cloud Ltd. HR Portal has a weak Password Recovery Mechanism for Forgotten Password. The reset password link sent out through e-mail, and the link will remain valid after the password has been reset and after the expected expiration date. An attacker with access to the browser history or has the line can thus use the URL again to change the password in order to take over the account.



Published: 2023-09-07
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update to 7.3.2023.0705

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-38437 Soar Cloud Ltd. HR Portal has a weak Password Recovery Mechanism for Forgotten Password. The reset password link sent out through e-mail, and the link will remain valid after the password has been reset and after the expected expiration date. An attacker with access to the browser history or has the line can thus use the URL again to change the password in order to take over the account.
History

Thu, 26 Sep 2024 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2024-09-26T19:50:30.068Z

Reserved: 2023-06-02T08:28:37.821Z

Link: CVE-2023-34357

cve-icon Vulnrichment

Updated: 2024-08-02T16:10:06.630Z

cve-icon NVD

Status : Modified

Published: 2023-09-07T03:15:08.263

Modified: 2024-11-21T08:07:05.380

Link: CVE-2023-34357

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses