qdPM 9.2 allows Cross-Site Request Forgery (CSRF) via the index.php/myAccount/update URI.
mitre·CWE-352·Published 2022-04-08