Vendor
IDURAR ERP CRM contains an authentication flaw in the updatePassword controller that allows any authenticated administrator to change the password of any other account, facilitating unauthorized account takeover.