Vendor
SkillHub versions prior to 0.2.22 contain an incorrect authorization vulnerability allowing authenticated attackers to perform account takeovers by exploiting the account merge flow.