Yimioa Password Modification Vulnerability in Web Security Configuration
Vulnerability
A vulnerability allowing unauthorized modification of Administrator passwords has been identified in Yimioa versions prior to 2024.07.04. This issue arises from incorrect access control in the WebSecurityConfig component, which enables attackers to arbitrarily change passwords.
Impact
Exploitation of this vulnerability allows for unauthorized changes to Administrator passwords, potentially leading to unauthorized administrative access.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
5.0exploitability
7.4remediation
0.0relevance
0.0threat
0.0urgency
2.9incentive
5.8Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
