Description
An issue was discovered in PowerJob through 3.2.2, allows attackers to change arbitrary user passwords via the id parameter to /appinfo/save.
Remediation
References
https://github.com/KFCFans/PowerJob/issues/99
Related Vulnerabilities
CVE-2022-31160 Vulnerability in maven package org.fujion.webjars:jquery-ui
CVE-2022-22881 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-base
CVE-2022-35961 Vulnerability in npm package @openzeppelin/contracts-upgradeable
CVE-2021-23558 Vulnerability in npm package bmoor
CVE-2022-31192 Vulnerability in maven package org.dspace:dspace-jspui