Vulnerabilities > CVE-2021-29394 - Incorrect Authorization vulnerability in Globalnorthstar Northstar Club Management 6.3
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
NONE Integrity impact
HIGH Availability impact
NONE Summary
Account Hijacking in /northstar/Admin/changePassword.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote authenticated users to change the password of any targeted user accounts via lack of proper authorization in the user-controlled "userID" parameter of the HTTP POST request.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |