← Back to CVE List

CVE-2021-29394

Published: 2022-02-04T19:15Z
Last Modified: 2024-11-21T06:01Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Account Hijacking in /northstar/Admin/changePassword.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote authenticated users to change the password of any targeted user accounts via lack of proper authorization in the user-controlled "userID" parameter of the HTTP POST request. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt