Medium
CVSS 6.4
Overview
account.asp in DUware DUclassmate 1.0 through 1.1 allows remote attackers to change the passwords for arbitrary users by modifying the MM_recordId parameter on the "My Account" page.
account.asp in DUware DUclassmate 1.0 through 1.1 allows remote attackers to cha...
account.asp in DUware DUclassmate 1.0 through 1.1 allows remote attackers to change the passwords for arbitrary users by modifying the MM_recordId parameter on the "My Account" page.
This vulnerability is rated 🟡 MEDIUM.
Recommended actions: