Impact
The vulnerability allows a user with a temporary authenticated session to change the account’s recovery email address without providing the current password. By setting a new email, the attacker can then trigger the password‑reset flow after the session expires, effectively converting a short‑term session compromise into persistent account takeover.
Affected Systems
The flaw exists in Laravel‑Backpack:CRUD versions 6.0.0 through 6.8.13 and 7.0.0 through 7.0.37. It has been remediated in releases 6.8.14 and 7.0.38, where the account‑info update route now requires password confirmation before altering the email field.
Risk and Exploitability
With a CVSS score of 6.5, the vulnerability is of moderate severity. The EPSS score is < 1%, indicating a very low but nonzero exploitation probability. It is not listed in CISA's KEV catalog. The attack vector requires that the adversary first obtain an authenticated session, but because the email can be changed without a password check, the attacker can subsequently reset the password after the session expires. This path offers persistent access, so while exploitation may depend on initial session acquisition, the potential impact is significant.
OpenCVE Enrichment
Github GHSA