Impact
The vulnerability allows an authenticated user to change the password of any non-administrator account without providing the current password. By supplying an arbitrary user id in the request body, an attacker can overwrite another user’s credentials, effectively taking control of that account. This results in unauthorized access to the victim’s resources and potential escalation of privileges if the compromised account has elevated permissions.
Affected Systems
The affected product is the zlt2000 microservices‑platform released up to and including version 6.0.0. The flaw resides in the /users/password endpoint, specifically in the SysUserController and SysUserServiceImpl classes of the user‑center module. Only non‑administrator accounts are vulnerable, while administrator accounts appear to retain protection through separate workflow. No other versions are listed as affected.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, but the EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, suggesting a relatively low likelihood of exploitation in the wild at this time. The likely attack vector requires an attacker to be authenticated within the system; however, once authenticated, the attacker can supply any user id and new password, allowing rapid compromise of other accounts. No additional network or privilege escalation prerequisites are noted in the available information.
OpenCVE Enrichment