CVE-2023-34357
Severity CVSS v4.0:
Pending analysis
Type:
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
Publication date:
07/09/2023
Last modified:
12/09/2023
Description
<br />
Soar Cloud Ltd. HR Portal has a weak Password Recovery Mechanism for Forgotten Password. The reset password link sent out through e-mail, and the link will remain valid after the password has been reset and after the expected expiration date. An attacker with access to the browser history or has the line can thus use the URL again to change the password in order to take over the account.<br />
<br />
<br />
<br />
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:scshr:hr_portal:7.3.2023.0510:*:*:*:*:*:*:* | ||
cpe:2.3:a:scshr:hr_portal:7.3.2023.0705:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page