Description
An issue was discovered in PowerJob through 3.2.2, allows attackers to change arbitrary user passwords via the id parameter to /appinfo/save.
Remediation
References
https://github.com/KFCFans/PowerJob/issues/99
Related Vulnerabilities
CVE-2020-13955 Vulnerability in maven package org.apache.calcite:calcite-core
CVE-2017-12648 Vulnerability in maven package com.liferay:com.liferay.frontend.taglib
CVE-2019-14863 Vulnerability in maven package org.webjars.npm:angular
CVE-2020-28487 Vulnerability in npm package vis-timeline
CVE-2020-28500 Vulnerability in maven package org.webjars.bower:lodash