Unverified Password Change in GitHub repository octoprint/octoprint prior to 1.8.3.
When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.
Link | Tags |
---|---|
https://huntr.dev/bounties/da6745e4-7bcc-4e9a-9e96-0709ec9f2477 | exploit third party advisory patch |
https://github.com/octoprint/octoprint/commit/1453076ee3e47fcab2dc73664ec2d61d3ef7fc4f | third party advisory patch |