PT-2026-21908 · Feiyuchuixue · Sz-Boot-Parent
Yuccun
·
Published
2026-02-25
·
Updated
2026-02-25
·
CVE-2026-3186
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
feiyuchuixue sz-boot-parent versions through 1.3.2-beta
Description
A flaw exists in the Password Reset Handler component of the software. This issue involves manipulation of the
userId argument within the '/api/admin/sys-user/reset/password/' file, leading to the use of a default password. The attack can be initiated remotely and has been publicly disclosed. The project developers have addressed this by adding authorization validation to the password reset interface, restricting password resets to users with appropriate permissions.Recommendations
Upgrade to version 1.3.3-beta.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sz-Boot-Parent