CVE-2023-34357

Severity CVSS v4.0:
Pending analysis
Type:
CWE-640 Weak Password Recovery Mechanism for Forgotten Password
Publication date:
07/09/2023
Last modified:
12/09/2023

Description

<br /> Soar Cloud Ltd. HR Portal has a weak Password Recovery Mechanism for Forgotten Password. The reset password link sent out through e-mail, and the link will remain valid after the password has been reset and after the expected expiration date. An attacker with access to the browser history or has the line can thus use the URL again to change the password in order to take over the account.<br /> <br /> <br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:scshr:hr_portal:7.3.2023.0510:*:*:*:*:*:*:*
cpe:2.3:a:scshr:hr_portal:7.3.2023.0705:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools