Weintek Weincloud v0.13.6 could allow an attacker to reset a password with the corresponding account’s JWT token only.
Solution:
Workaround:
The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak.
Link | Tags |
---|---|
https://www.cisa.gov/news-events/ics-advisories/icsa-23-199-04 | third party advisory us government resource |