The GPM from WormHole Tech has an Unverified Password...
Critical severity
Unreviewed
Published
May 12, 2025
to the GitHub Advisory Database
•
Updated May 12, 2025
Description
Published by the National Vulnerability Database
May 12, 2025
Published to the GitHub Advisory Database
May 12, 2025
Last updated
May 12, 2025
The GPM from WormHole Tech has an Unverified Password Change vulnerability, allowing unauthenticated remote attackers to change any user's password and use the modified password to log into the system.
References