Impact
An unauthenticated attacker can craft a cross‑site request that changes an authenticated user's password without providing a CSRF token or the current password. The vulnerability lies in the /api/users/{id}/password endpoint and allows the attacker to overwrite a target account’s password, effectively hijacking the account and gaining full access to the affected system.
Affected Systems
The flaw affects Semaphore UI versions earlier than 2.18.21. The affected product is Semaphore UI (semaphoreui:semaphore).
Risk and Exploitability
The CVSS score of 8.3 classifies the flaw as high severity. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog. The attack requires an authenticated user to interact with a malicious site to trigger a CSRF request. The attacker does not need to guess or brute‑force the password, and the change is accepted immediately without confirmation or additional checks.
OpenCVE Enrichment