Arbitrary Password Change in PowerJob Affected by Security Flaw
CVE-2020-28865
7.5HIGH
What is CVE-2020-28865?
An identified vulnerability in PowerJob enables attackers to exploit the system by modifying any user's password through manipulation of the 'id' parameter in the /appinfo/save endpoint. This weakness poses a significant threat to user security, as it can be leveraged to gain unauthorized access to accounts, making it essential for users and administrators to update to the latest version and apply necessary security measures.
