Monstra CMS through 3.0.4 allows remote authenticated users to take over arbitrary user accounts via a modified login parameter to an edit…
mitre·CWE-425·Published 2020-03-07